First published: Wed Oct 31 2007(Updated: )
Stack-based buffer overflow in RealNetworks RealPlayer 10 and possibly 10.5, and RealOne Player 1 and 2, for Windows allows remote attackers to execute arbitrary code via a crafted playlist (PLS) file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
RealPlayer | =10.5-6.0.12.1040 | |
RealPlayer | =10.5-6.0.12.1741 | |
RealNetworks RealPlayer | =2.0 | |
RealNetworks RealPlayer | =1.0 | |
RealPlayer | =10.5-6.0.12.1578 | |
RealPlayer | =10.5-6.0.12.1698 | |
RealPlayer | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-4599 is rated as critical due to its potential for remote code execution.
To fix CVE-2007-4599, users should update to the latest version of RealPlayer or RealOne Player that does not contain this vulnerability.
CVE-2007-4599 affects RealNetworks RealPlayer versions 10.0 to 10.5 and RealOne Player versions 1 and 2.
Yes, CVE-2007-4599 can be exploited remotely through a specially crafted playlist file.
The potential impacts of CVE-2007-4599 include unauthorized execution of arbitrary code on the affected system.