CVE-2007-2497: High severity RealNetworks RealPlayer vulnerability
Published May 4, 2007
·Updated
RealNetworks RealPlayer 10 Gold allows remote attackers to cause a denial of service (memory consumption) via a certain .ra file. NOTE: this issue was referred to as a "memory leak," but it is not clear if this is correct.
Affected Software
1 affected component
RealNetworks RealPlayer<=10.0
Event History
May 4, 2007
CVE Published
12:19 AM
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-2497?
CVE-2007-2497 is classified as a denial of service vulnerability due to memory consumption.
2
How do I fix CVE-2007-2497?
To fix CVE-2007-2497, update to a version of RealPlayer that is newer than 10.0, as it mitigates the issue.
3
What type of attack is CVE-2007-2497 associated with?
CVE-2007-2497 is associated with remote attackers using specially crafted .ra files to cause denial of service.
4
Which software versions are affected by CVE-2007-2497?
CVE-2007-2497 affects RealPlayer 10 Gold versions up to and including 10.0.
5
What behavior is seen when exploiting CVE-2007-2497?
Exploitation of CVE-2007-2497 can lead to excessive memory consumption, potentially crashing the application.