The RealNetworks RealAudioObjects.RealAudio ActiveX control in rmoc3260.dll, as shipped with RealPlayer 11, allows remote attackers to cause a denial of service (browser crash) via a certain argument to the GetSourceTransport method.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/26660 | vdb entry |
http://www.securityfocus.com/archive/1/484401/100/0/threaded | mailing list |
http://securityreason.com/securityalert/3415 | third party advisory |
http://www.safehack.com/Advisory/realpdos.txt | url repurposed exploit |
https://exchange.xforce.ibmcloud.com/vulnerabilities/38778 | vdb entry |