PT-2007-6621 · Realnetworks · Realplayer+1

Will Dormann

·

Publicado

2007-10-20

·

Atualizado

2017-07-29

·

CVE-2007-5601

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions RealPlayer versions prior to 10.5, including 10, RealOne Player, and RealOne Player 2 RealPlayer version 11 beta
Description A stack-based buffer overflow issue exists in the Database Component of MPAMedia.dll. This allows remote attackers to execute arbitrary code via certain playlist names. The issue can be demonstrated through the import method to the IERPCtl ActiveX control in ierpplug.dll.
Recommendations For RealPlayer versions prior to 10.5, including 10, RealOne Player, and RealOne Player 2, update to a version later than 10.5 to resolve the issue. For RealPlayer version 11 beta, update to a non-beta version to resolve the issue. As a temporary workaround, consider restricting access to the IERPCtl ActiveX control in ierpplug.dll to minimize the risk of exploitation.

Exploit

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-5601

Produtos afetados

Realone Player
Realplayer