CVE-2007-5601
Summary
| CVE | CVE-2007-5601 |
|---|---|
| State | PUBLISHED |
| Assigner | certcc |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-10-20 20:17:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Stack-based buffer overflow in the Database Component in MPAMedia.dll in RealNetworks RealPlayer 10.5 and 11 beta, and earlier versions including 10, RealOne Player, and RealOne Player 2, allows remote attackers to execute arbitrary code via certain playlist names, as demonstrated via the import method to the IERPCtl ActiveX control in ierpplug.dll. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:M/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Realnetworks | Realplayer | 10.0 | All | All | All |
| Application | Realnetworks | Realplayer | 10.5 | All | All | All |
| Application | Realnetworks | Realplayer | 11_beta | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| RealPlayer Playlist Handling Buffer Overflow Vulnerability - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Symantec Security Response Weblog: RealPlayer Exploit On The Loose | af854a3a-2127-422b-91ae-364da2661108 | www.symantec.com | |
| US-CERT Technical Cyber Security Alert TA07-297A -- RealNetworks RealPlayer ActiveX Playlist Buffer Overflow | af854a3a-2127-422b-91ae-364da2661108 | www.us-cert.gov | US Government Resource |
| RealPlayer ierpplug.dll ActiveX Control Import Playlist Name Stack Buffer Overflow Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| RealPlayer Input Validation Flaw in 'ierpplug.dll' Lets Remote Users Execute Arbitrary Code - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| VU#871673 - RealPlayer playlist name stack buffer overflow | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | US Government Resource |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| NASA Bans IE? - Roger's Information Security Blog | af854a3a-2127-422b-91ae-364da2661108 | www.infosecblog.org | |
| RealPlayer and StarSearch by Real Official Homepage — Real.com | af854a3a-2127-422b-91ae-364da2661108 | service.real.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2007-10-23 | Mark J Cox | Not vulnerable. This issue did not affect versions of RealPlayer as shipped with Red Hat Enterprise Linux 3 and 4 Extras or with Red Hat Enterprise Linux 5 Supplementary. |
There are currently no legacy QID mappings associated with this CVE.