Use-after-free vulnerability in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.5, RealPlayer SP 1.0 through 1.1.5, and RealPlayer Enterprise 2.0 through 2.1.5, when an Embedded RealPlayer is used, allows remote attackers to execute arbitrary code via vectors related to a modal dialog.
References
Link | Resource |
---|---|
http://service.real.com/realplayer/security/08162011_player/en/ | Vendor Advisory |
http://www.securitytracker.com/id?1025943 |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Information
Published : 2011-08-18 16:55
Updated : 2011-10-05 19:50
NVD link : CVE-2011-2955
Mitre link : CVE-2011-2955
JSON object : View
CWE
CWE-399
Resource Management Errors
Products Affected
realnetworks
- realplayer_sp
- realplayer