CVE-2007-4599: Buffer Overflow
Published Oct 31, 2007
·Updated
Stack-based buffer overflow in RealNetworks RealPlayer 10 and possibly 10.5, and RealOne Player 1 and 2, for Windows allows remote attackers to execute arbitrary code via a crafted playlist (PLS) file.
Affected Software
7 affected components
RealNetworks RealPlayer=10.5-6.0.12.1040
RealNetworks RealPlayer=10.5-6.0.12.1741
RealNetworks RealOne Player=2.0
RealNetworks RealOne Player=1.0
RealNetworks RealPlayer=10.5-6.0.12.1578
RealNetworks RealPlayer=10.5-6.0.12.1698
RealNetworks RealPlayer=10.0
Remediation
Patch Available
Event History
Oct 31, 2007
CVE Published
05:46 PM
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-4599?
CVE-2007-4599 is rated as critical due to its potential for remote code execution.
2
How do I fix CVE-2007-4599?
To fix CVE-2007-4599, users should update to the latest version of RealPlayer or RealOne Player that does not contain this vulnerability.
3
What software is affected by CVE-2007-4599?
CVE-2007-4599 affects RealNetworks RealPlayer versions 10.0 to 10.5 and RealOne Player versions 1 and 2.
4
Can CVE-2007-4599 be exploited remotely?
Yes, CVE-2007-4599 can be exploited remotely through a specially crafted playlist file.
5
What are the potential impacts of CVE-2007-4599?
The potential impacts of CVE-2007-4599 include unauthorized execution of arbitrary code on the affected system.