Vulnerability Name: | CVE-2007-5400 (CCN-43996) | ||||||||||||||||
Assigned: | 2007-10-12 | ||||||||||||||||
Published: | 2008-07-25 | ||||||||||||||||
Updated: | 2018-10-30 | ||||||||||||||||
Summary: | Heap-based buffer overflow in the Shockwave Flash (SWF) frame handling in RealNetworks RealPlayer 10.5 Build 6.0.12.1483 might allow remote attackers to execute arbitrary code via a crafted SWF file. | ||||||||||||||||
CVSS v3 Severity: | 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||||||||||
CVSS v2 Severity: | 9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C) 6.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
6.9 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||||||||||
Vulnerability Type: | CWE-119 | ||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2007-5400 Source: SUSE Type: UNKNOWN SUSE-SR:2009:011 Source: CCN Type: RHSA-2008-0812 Critical: RealPlayer security update Source: CCN Type: SA27620 RealNetworks RealPlayer Multiple Vulnerabilities Source: SECUNIA Type: Vendor Advisory 27620 Source: CCN Type: SA31321 Red Hat Extras and Supplementary RealPlayer Vulnerability Source: SECUNIA Type: UNKNOWN 31321 Source: SECUNIA Type: UNKNOWN 35416 Source: CCN Type: SA56013 Gentoo win32codecs SWF Buffer Overflow Vulnerability Source: CCN Type: Secunia Research 25/07/2008 RealNetworks RealPlayer SWF Frame Handling Buffer Overflow Source: MISC Type: Vendor Advisory http://secunia.com/secunia_research/2007-93/advisory/ Source: SREASON Type: UNKNOWN 4048 Source: CCN Type: SECTRACK ID: 1020562 RealPlayer Heap Overflow in Processing SWF File Frames Lets Remote Users Execute Arbitrary Code Source: CCN Type: Real Player Customer Support Web site RealNetworks, Inc. Releases Update to Address Security Vulnerabilities Source: CONFIRM Type: UNKNOWN http://service.real.com/realplayer/security/07252008_player/en/ Source: CCN Type: ASA-2008-329 RealPlayer security update (RHSA-2008-0812) Source: CCN Type: GLSA-200809-03 RealPlayer: Buffer overflow Source: CCN Type: US-CERT VU#298651 RealNetworks RealPlayer Shockwave Flash (SWF) file vulnerability Source: CERT-VN Type: US Government Resource VU#298651 Source: REDHAT Type: UNKNOWN RHSA-2008:0812 Source: BUGTRAQ Type: UNKNOWN 20080725 Secunia Research: RealPlayer SWF Frame Handling Buffer Overflow Source: BID Type: UNKNOWN 30370 Source: CCN Type: BID-30370 RealNetworks RealPlayer SWF File Heap Based Buffer Overflow Vulnerability Source: SECTRACK Type: UNKNOWN 1020562 Source: VUPEN Type: UNKNOWN ADV-2008-2194 Source: XF Type: UNKNOWN realplayer-swf-frame-bo(43996) Source: XF Type: UNKNOWN realplayer-swf-frame-bo(43996) Source: SUSE Type: SUSE-SR:2009:011 SUSE Security Summary Report | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: Configuration RedHat 2: Configuration RedHat 3: Denotes that component is vulnerable | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |