First published: Mon Jul 28 2008(Updated: )
Heap-based buffer overflow in the Shockwave Flash (SWF) frame handling in RealNetworks RealPlayer 10.5 Build 6.0.12.1483 might allow remote attackers to execute arbitrary code via a crafted SWF file.
Credit: PSIRT-CNA@flexerasoftware.com
Affected Software | Affected Version | How to fix |
---|---|---|
Real RealPlayer | =10.1 | |
RealPlayer | =10.0 | |
RealPlayer | =10.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-5400 is considered critical because it enables remote attackers to execute arbitrary code on affected systems.
To mitigate CVE-2007-5400, users should update RealPlayer to a version that is not affected by the vulnerability.
CVE-2007-5400 impacts RealPlayer versions 10.0, 10.1, and 10.5.
Yes, CVE-2007-5400 can be exploited through malicious SWF files hosted on a website.
Exploitations of CVE-2007-5400 can lead to arbitrary code execution, potentially compromising the affected system.