CVE-2007-6224: Input Validation
Published Dec 4, 2007
·Updated
The RealNetworks RealAudioObjects.RealAudio ActiveX control in rmoc3260.dll, as shipped with RealPlayer 11, allows remote attackers to cause a denial of service (browser crash) via a certain argument to the GetSourceTransport method.
Affected Software
6 affected components
Microsoft Windows Vista
Microsoft Windows XP=sp2
RealNetworks RealPlayer=11.0
All of the following
Any of the following
Microsoft Windows Vista
Microsoft Windows XP=sp2
RealNetworks RealPlayer=11.0
Event History
Dec 4, 2007
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Data Sourced
06:46 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2007-6224?
CVE-2007-6224 is classified as a denial-of-service vulnerability allowing remote attackers to crash browsers.
2
How does CVE-2007-6224 exploit RealPlayer?
CVE-2007-6224 exploits the RealAudio ActiveX control via a malformed argument to the GetSourceTransport method.
3
Which version of RealPlayer is affected by CVE-2007-6224?
CVE-2007-6224 affects RealPlayer version 11.0.
4
Which operating systems are vulnerable to CVE-2007-6224?
CVE-2007-6224 impacts systems running RealPlayer 11.0 on Windows XP SP2.
5
How do I mitigate the effects of CVE-2007-6224?
To mitigate CVE-2007-6224, it is recommended to update RealPlayer to the latest version or disable the RealAudio ActiveX control.