First published: Wed Oct 31 2007(Updated: )
Heap-based buffer overflow in RealNetworks RealPlayer 8, 10, 10.1, and possibly 10.5; RealOne Player 1 and 2; and RealPlayer Enterprise allows remote attackers to execute arbitrary code via a RAM (.ra or .ram) file with a large size value in the RA header.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
RealPlayer | =10.0-10.0.7 | |
RealPlayer | =10.5-6.0.12.1040 | |
RealPlayer | =10.5-6.0.12.1741 | |
RealNetworks RealPlayer | =2.0 | |
RealPlayer | =10.0-10.0.9 | |
RealPlayer | =8.0 | |
RealNetworks RealPlayer | =1.0 | |
RealPlayer | ||
RealPlayer | =10.1-10.0.0._481 | |
RealPlayer | =10.1-10.0.0.396 | |
RealPlayer | =10.5-6.0.12.1578 | |
RealPlayer | =10.0-10.0.8 | |
RealPlayer | =10.5-6.0.12.1698 | |
RealPlayer | =10.0-10.0.0.305 | |
RealPlayer | =10.1-10.0.0.412 | |
RealPlayer | =10.0-10.0.0.352 | |
RealPlayer | =10.0-10.0.6 | |
RealNetworks RealPlayer | ||
RealPlayer | =10.0-10.0.5 | |
RealPlayer | =10.0 | |
RealPlayer | =10.0-10.0.0.331 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-2264 has a high severity level as it allows remote attackers to execute arbitrary code via specially crafted RAM files.
CVE-2007-2264 affects RealPlayer 8, 10, 10.1, and possibly 10.5, as well as RealOne Player 1 and 2.
To fix CVE-2007-2264, update your RealPlayer to the latest version provided by RealNetworks.
CVE-2007-2264 primarily impacts Windows and Linux systems running affected versions of RealPlayer.
Yes, CVE-2007-2264 can lead to data loss as it allows arbitrary code execution, which may compromise system integrity.