PT-2007-6621 · Realnetworks · Realplayer+1
Will Dormann
·
Publicado
2007-10-20
·
Atualizado
2017-07-29
·
CVE-2007-5601
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
RealPlayer versions prior to 10.5, including 10, RealOne Player, and RealOne Player 2
RealPlayer version 11 beta
Description
A stack-based buffer overflow issue exists in the Database Component of MPAMedia.dll. This allows remote attackers to execute arbitrary code via certain playlist names. The issue can be demonstrated through the import method to the
IERPCtl ActiveX control in ierpplug.dll.Recommendations
For RealPlayer versions prior to 10.5, including 10, RealOne Player, and RealOne Player 2, update to a version later than 10.5 to resolve the issue.
For RealPlayer version 11 beta, update to a non-beta version to resolve the issue.
As a temporary workaround, consider restricting access to the
IERPCtl ActiveX control in ierpplug.dll to minimize the risk of exploitation.Exploit
Correção
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Realone Player
Realplayer