Tuesday, October 30, 2007

RealNetworks RealPlayer Format String

An attacker could remotely execute code on a vulnerable system because of an exploitable format string vulnerability found in Linux and Unix versions of the Helix Player and RealPlayer. To exploit this vulnerability, simply specify an invalid value for the "time format attribute" in a realpix file.