APP: RealNetworks RealPlayer SMIL Wallclock Stack Overflow

This signature detects attempts to exploit a known vulnerability in RealNetworks RealPlayer. A successful attack could allow the attacker to execute arbitrary code on the targeted system. Failed exploit attempts could result in a denial of service condition.

Extended Description

RealPlayer and HelixPlayer are prone to a buffer-overflow vulnerability because the applications fail to bounds-check user-supplied data before copying it into an insufficiently sized buffer. Successfully exploiting this issue allows remote attackers to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed exploit attempts likely result in denial-of-service conditions.

Affected Products

Real_networks realplayer_10_for_linux

Short Name
APP:REAL:SMIL-WALLCLOCK-OF
Severity
Minor
Recommended
False
Recommended Action
Drop
Category
APP
Keywords
CVE-2007-3410 Overflow RealNetworks RealPlayer SMIL Stack Wallclock bid:24658
Release Date
07/23/2007
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3724
False Positive
Unknown
Vendors

Red_hat

Gentoo

Real_networks

CVSS Score

9.3

Found a potential security threat?