9.3
CVSSv2

CVE-2007-5601

Published: 20/10/2007 Updated: 29/07/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 940
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Stack-based buffer overflow in the Database Component in MPAMedia.dll in RealNetworks RealPlayer 10.5 and 11 beta, and previous versions versions including 10, RealOne Player, and RealOne Player 2, allows remote malicious users to execute arbitrary code via certain playlist names, as demonstrated via the import method to the IERPCtl ActiveX control in ierpplug.dll.

Vulnerable Product Search on Vulmon Subscribe to Product

realnetworks realplayer 10.0

realnetworks realplayer 10.5

realnetworks realplayer 11_beta

Exploits

## # $Id: realplayer_importrb 9262 2010-05-09 17:45:00Z jduck $ ## ## # This file is part of the Metasploit Framework and may be subject to # redistribution and commercial restrictions Please see the Metasploit # Framework web site for more information on licensing and terms of use # metasploitcom/framework/ ## require 'msf/core' clas ...
source: wwwsecurityfocuscom/bid/26130/info RealPlayer is prone to a stack-based buffer-overflow vulnerability because it fails to perform adequate boundary checks of user-supplied input before copying it to an insufficiently sized memory buffer Attackers can exploit this issue to execute arbitrary code in the context of the application ...