Vulnerabilities > CVE-2007-4904 - Numeric Errors vulnerability in Realnetworks Helix Player and Realplayer

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN
realnetworks
CWE-189
exploit available

Summary

RealNetworks RealPlayer 10.1.0.3114 and earlier, and Helix Player 1.0.6.778 on Fedora Core 6 (FC6) and possibly other platforms, allow user-assisted remote attackers to cause a denial of service (application crash) via a malformed .au file that triggers a divide-by-zero error.

Common Weakness Enumeration (CWE)

Exploit-Db

descriptionRealPlayer 11 Malformed AU File Denial of Service Exploit. CVE-2007-4904,CVE-2007-6235. Dos exploit for windows platform
fileexploits/windows/dos/4683.py
idEDB-ID:4683
last seen2016-01-31
modified2007-12-01
platformwindows
port
published2007-12-01
reporterNtWaK0
sourcehttps://www.exploit-db.com/download/4683/
titleRealPlayer 11 Malformed AU File Denial of Service Exploit
typedos

Statements

contributorMark J Cox
lastmodified2007-09-18
organizationRed Hat
statementWe do not consider a crash of a client application such as RealPlayer or Helix Player to be a security issue.