FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2007-2263

This CVE name corresponds to:

Entered Topic
2008-01-04 linux-realplayer -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2007-2263
Phase Assigned(20070425)

Description

Heap-based buffer overflow in RealNetworks RealPlayer 10.0, 10.1, and possibly 10.5, RealOne Player, and RealPlayer Enterprise allows remote attackers to execute arbitrary code via an SWF (Flash) file with malformed record headers.

References

Source Reference
BUGTRAQ 20071031 ZDI-07-061: RealNetworks RealPlayer SWF Processing Remote Code Execution Vulnerability
MISC http://www.zerodayinitiative.com/advisories/ZDI-07-061.html
CONFIRM http://service.real.com/realplayer/security/10252007_player/en/
VIM 20071030 RealPlayer Updates of October 25, 2007
BID 26214
BID 26284
OVAL oval:org.mitre.oval:def:11432
VUPEN ADV-2007-3628
OSVDB 38344
SECTRACK 1018866
SECUNIA 27361
XF realplayer-swf-bo(37436)