Overview
Multiple Real media players fail to properly validate RealJukebox Metadata Package (RMP) files which may permit an attacker to download and execute arbitrary code on the user's system.
Description
| RealNetworks Real media players are multimedia applications that allow users to view local and remote audio/video content. These players support multiple media types including RealJukebox Metadata Package (RMP) files. There is a vulnerability in the way Real players validate RMP files. This flaw could be used by an attacker to download and execute arbitrary code on the user's system by creating a specially crafted RMP file. According to RealNetworks Security Advisory, this vulnerability affects the following products: 
 | 
Impact
| An attacker could download and execute arbitrary code on a user's system. | 
Solution
| Upgrade | 
Vendor Information
CVSS Metrics
| Group | Score | Vector | 
|---|---|---|
| Base | ||
| Temporal | ||
| Environmental | 
References
Acknowledgements
Thanks to RealNetworks and Secunia for information contained in their security advisories.
This document was written by Damon Morda.
Other Information
| CVE IDs: | None | 
| Severity Metric: | 11.07 | 
| Date Public: | 2004-02-05 | 
| Date First Published: | 2004-02-06 | 
| Date Last Updated: | 2004-02-06 17:56 UTC | 
| Document Revision: | 24 |