Intrusion Prevention

RealNetworks.RealPlayer.MP4.File.Parsing.Memory.Corruption

Description

This indicates an attack attempt against a buffer overflow vulnerability in RealNetworks RealPlayer.
The vulnerability is caused by an error when the vulnerable software handles a specifically crafted MP4 file with the "Sample Size" member of a 'stsz' structure having an overly long size value. An attacker can trick an unsuspecting user into opening a MP4 file and execute arbitrary code within the context of the application.

Affected Products

RealPlayer version v18.1.5.705 and earlier

Impact

System Compromise: Remote attackers could gain control of vulnerable systems.

Recommended Actions

Apply the latest update from the vendor.
https://customer.real.com/hc/en-us/articles/214793317

CVE References

CVE-2016-9929