CVE-2007-5601
Last modified
CVE-2007-5601 is a vulnerability of currently unknown severity. Stack-based buffer overflow in the Database Component in MPAMedia.dll in RealNetworks RealPlayer 10.5 and 11 beta, and earlier versions including 10, RealOne Player, and RealOne Player 2, allows remote attackers to execute arbitrary code via certain playlist names, as demonstrated via the import method to the IERPCtl ActiveX control in ierpplug.dll.. EPSS estimates a 42.37% chance of exploitation in the next 30 days.
Description
Stack-based buffer overflow in the Database Component in MPAMedia.dll in RealNetworks RealPlayer 10.5 and 11 beta, and earlier versions including 10, RealOne Player, and RealOne Player 2, allows remote attackers to execute arbitrary code via certain playlist names, as demonstrated via the import method to the IERPCtl ActiveX control in ierpplug.dll.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Realnetworks | Realplayer | 10.0 |
| Realnetworks | Realplayer | 10.5 |
| Realnetworks | Realplayer | 11_beta |
References
- http://secunia.com/advisories/27248Vendor Advisory
- http://www.kb.cert.org/vuls/id/871673US Government Resource
- http://www.us-cert.gov/cas/techalerts/TA07-297A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2007/3548Vendor Advisory
- http://secunia.com/advisories/27248Vendor Advisory
- http://www.kb.cert.org/vuls/id/871673US Government Resource
- http://www.us-cert.gov/cas/techalerts/TA07-297A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2007/3548Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-5601?
How severe is CVE-2007-5601?
How do I fix CVE-2007-5601?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-5595CRLF injection vulnerability in the drupal_goto function in …
- CVE-2007-5596The core Upload module in Drupal 4.7.x before 4.7.8 and 5.x …
- CVE-2007-5597The hook_comments API in Drupal 4.7.x before 4.7.8 and 5.x b…
- CVE-2007-5598Cross-site scripting (XSS) vulnerability in Weblinks for Dru…
- CVE-2007-5599Multiple PHP remote file inclusion vulnerabilities in awrate…
- CVE-2007-5600Incomplete blacklist vulnerability in index.php in Artmedic …
- CVE-2007-5602Multiple stack-based buffer overflows in SwiftView Viewer be…
- CVE-2007-5603Stack-based buffer overflow in the SonicWall SSL-VPN NetExte…
- CVE-2007-5604Buffer overflow in the ExtractCab function in the HPISDataMa…
- CVE-2007-5605Buffer overflow in the GetFileTime function in the HPISDataM…
- CVE-2007-5606Buffer overflow in the MoveFile function in the HPISDataMana…
- CVE-2007-5607Buffer overflow in the RegistryString function in the HPISDa…
Are you affected by CVE-2007-5601?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
