Integer underflow in the real_get_rdt_chunk function in real.c, as used in modules/access/rtsp/real.c in VideoLAN VLC media player before 1.0.1 and stream/realrtsp/real.c in MPlayer before r29447, allows remote attackers to execute arbitrary code via a crafted length value in an RDT chunk header.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2010-2081
http://seclists.org/fulldisclosure/2009/Jul/418
http://openwall.com/lists/oss-security/2010/06/04/4
http://git.videolan.org/?p=vlc.git%3Ba=commit%3Bh=dc74600c97eb834c08674676e209afa842053aca