The RealAudioObjects.RealAudio ActiveX control in rmoc3260.dll in RealNetworks RealPlayer Enterprise, RealPlayer 10, RealPlayer 10.5 before build 6.0.12.1675, and RealPlayer 11 before 11.0.3 build 6.0.14.806 does not properly manage memory for the (1) Console or (2) Controls property, which allows remote attackers to execute arbitrary code or cause a denial of service (browser crash) via a series of assignments of long string values, which triggers an overwrite of freed heap memory.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2008-03-12T17:00:00
Updated: 2024-08-07T08:17:33.628Z
Reserved: 2008-03-12T00:00:00
Link: CVE-2008-1309
Vulnrichment
No data.
NVD
Status : Modified
Published: 2008-03-12T17:44:00.000
Modified: 2024-11-21T00:44:13.993
Link: CVE-2008-1309
Redhat
No data.