PT-2007-6621 · Realnetworks · Realplayer+1
Will Dormann
·
Published
2007-10-20
·
Updated
2017-07-29
·
CVE-2007-5601
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
RealPlayer versions prior to 10.5, including 10, RealOne Player, and RealOne Player 2
RealPlayer version 11 beta
Description
A stack-based buffer overflow issue exists in the Database Component of MPAMedia.dll. This allows remote attackers to execute arbitrary code via certain playlist names. The issue can be demonstrated through the import method to the
IERPCtl ActiveX control in ierpplug.dll.Recommendations
For RealPlayer versions prior to 10.5, including 10, RealOne Player, and RealOne Player 2, update to a version later than 10.5 to resolve the issue.
For RealPlayer version 11 beta, update to a non-beta version to resolve the issue.
As a temporary workaround, consider restricting access to the
IERPCtl ActiveX control in ierpplug.dll to minimize the risk of exploitation.Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Realone Player
Realplayer