CVE Vulnerabilities

CVE-2007-5080

Published: Oct 31, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Integer overflow in RealNetworks RealPlayer 10 and 10.5, RealOne Player 1, and RealPlayer Enterprise for Windows allows remote attackers to execute arbitrary code via a crafted Lyrics3 2.00 tag in an MP3 file, resulting in a heap-based buffer overflow.

Affected Software

NameVendorStart VersionEnd Version
Realone_playerRealnetworks1.0 (including)1.0 (including)
Realone_playerRealnetworks2.0 (including)2.0 (including)
RealplayerRealnetworks10.0 (including)10.0 (including)
RealplayerRealnetworks10.5-6.0.12.1040 (including)10.5-6.0.12.1040 (including)
RealplayerRealnetworks10.5-6.0.12.1578 (including)10.5-6.0.12.1578 (including)
RealplayerRealnetworks10.5-6.0.12.1698 (including)10.5-6.0.12.1698 (including)
RealplayerRealnetworks10.5-6.0.12.1741 (including)10.5-6.0.12.1741 (including)
Realplayer_enterpriseRealnetworks**

References