Korean
<< Back
VID 50030
Severity 40
Port 139,445
Protocol TCP
Class SMB
Detailed Description According to its build number, the installed version of RealPlayer on the remote Windows host is earlier than 15.0.6.14. As such, it is affected by multiple vulnerabilities :

- A buffer overflow error exists related to 'AAC' handling, specifically unpacking of the stream data. (CVE-2012-2407)

- A heap-corruption error exists related to the 'AAC SDK' decoding. (CVE-2012-2408)

- Two unspecified buffer overflow errors exist related to 'RealMedia'. (CVE-2012-2409, CVE-2012-2410)

- A divide-by-zero error exists related to 'RealAudio' and codec frame size. (CVE-2012-3234)

* Note: This check solely relied on the banner of the remote Web server to assess this vulnerability, so this might be a false positive.

* References:
http://service.real.com/realplayer/security/09072012_player/en/

* Platforms Affected:
RealPlayer for Windows Build Before 15.0.6.14
Microsoft Windows Any version
Recommendation Upgrade to the latest version available from the RealNetworks Web site at http://kr.real.com/?error=/plus
Related URL CVE-2012-2407,CVE-2012-2408,CVE-2012-2409,CVE-2012-2410,CVE-2012-3234 (CVE)
Related URL 55473 (SecurityFocus)
Related URL (ISS)