PT-2007-6621 · Realnetworks · Realplayer+1

Will Dormann

·

Published

2007-10-20

·

Updated

2017-07-29

·

CVE-2007-5601

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions RealPlayer versions prior to 10.5, including 10, RealOne Player, and RealOne Player 2 RealPlayer version 11 beta
Description A stack-based buffer overflow issue exists in the Database Component of MPAMedia.dll. This allows remote attackers to execute arbitrary code via certain playlist names. The issue can be demonstrated through the import method to the IERPCtl ActiveX control in ierpplug.dll.
Recommendations For RealPlayer versions prior to 10.5, including 10, RealOne Player, and RealOne Player 2, update to a version later than 10.5 to resolve the issue. For RealPlayer version 11 beta, update to a non-beta version to resolve the issue. As a temporary workaround, consider restricting access to the IERPCtl ActiveX control in ierpplug.dll to minimize the risk of exploitation.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-5601

Affected Products

Realone Player
Realplayer