RealNetworks RealPlayer before 16.0.0.282 and RealPlayer SP 1.0 through 1.1.5 allow remote attackers to execute arbitrary code via a RealAudio file that triggers access to an invalid pointer.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2012-5573
http://service.real.com/realplayer/security/12142012_player/en/