CVE-2007-3410
Stack-based buffer overflow in the SmilTimeValue::parseWallClockValue function in smlprstime.cpp in RealNetworks RealPlayer 10, 10.1, and possibly 10.5, RealOne Player, RealPlayer Enterprise, and Helix Player 10.5-GOLD and 10.0.5 through 10.0.8, allows remote attackers to execute arbitrary code via an SMIL (SMIL2) file with a long wallclock value.
- Affected products
- Helix Player, Realone Player, Realplayer, Realplayer Enterprise, Red Hat
- Realnetworks Helix Player
- = 10.0.5, 10.0.6, 10.0.7, 10.0.8, 10.5-gold
- Realnetworks Realone Player
- All versions
- Realnetworks Realplayer
- = 10.0, 10.1, 10.5
- Realnetworks Realplayer Enterprise
- All versions
- Fix
- Available
- CVSS 2.0
- 9.3 HIGH
- EPSS
- 36.1% (98th percentile)
- Weakness
- CWE-119
- NVD status
- Modified
- Published
- 2007-06-26
CVE-2007-3410 at NVD
7 known exploits for CVE-2007-3410
Proof-of-concept code and exploit modules indexed by Sploitus
RealPlayer SMIL file wallclock buffer overflow
RealPlayer SMIL file wallclock buffer overflow
RealPlayer SMIL file wallclock buffer overflow
RealPlayer SMIL file wallclock buffer overflow
RealPlayer/HelixPlayer ParseWallClockValue函数栈缓冲区溢出漏洞
RealNetworks RealPlayer/HelixPlayer - SMIL wallclock Stack Overflow (PoC)
DSquare Exploit Pack: D2SEC_REAL_WALLCLOCK