>> RealNetworks RealPlayer and HelixPlayer SMIL Wallclock Stack Overflow Vulnerability
Title : RealNetworks RealPlayer and HelixPlayer SMIL Wallclock Stack Overflow Vulnerability VUPEN ID : VUPEN/ADV-2007-2339 CVE ID : CVE-2007-3410
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-06-26
Technical Description
A vulnerability has been identified in RealNetworks RealPlayer and HelixPlayer, which could be exploited by remote attackers to cause a denial of service or take complete control of an affected system. This issue is caused by a buffer overflow error in the "SmilTimeValue::parseWallClockValue()" function when handling time formats, which could be exploited by remote attackers to crash an affected application or execute arbitrary code by tricking a user into opening a specially crafted SMIL file or visiting a malicious web page.