Note: This page is part of the archive.

This document is part of the US-CERT website archive. These documents are no longer updated and may contain outdated information. Links may also no longer function. Please contact if you have any questions about the US-CERT website archive.

Alert (SA07-297A)

RealNetworks RealPlayer ActiveX Playlist Buffer Overflow

Systems Affected

  • RealOne Player
  • RealOne Player v2
  • RealPlayer 10
  • RealPlayer 10.5
  • RealPlayer 11 beta


RealNetworks RealPlayer for Microsoft Windows contains a vulnerability that could allow an attacker to take control of your computer when you visit a malicious web site.


Upgrade and install a patch

RealNetworks has released a patch to address this vulnerability. Information about the vulnerability and the patch is available in RealPlayer Security Vulnerability and Security Update for Real Player.

  • RealPlayer 10.5 and RealPlayer 11 beta users should install the patch.
  • RealOne Player v2, and RealPlayer 10 users should upgrade to RealPlayer 10.5 or RealPlayer 11 beta and then install the patch.
Windows versions of RealPlayer 8 and earlier are not affected. Mactintosh and Linux versions of RealPlayer are not affected.

Disable ActiveX for untrusted web sites

Disabling ActiveX in the Internet Zone (or any zone used by an attacker) reduces the chances of exploitation of this and other vulnerabilities. Instructions for disabling ActiveX in the Internet Zone can be found in the "Securing Your Web Browser" document.

There are public reports that this vulnerability is being actively exploited.


A buffer overflow in the way RealPlayer handles playlists received from an ActiveX control on a web page could allow an attacker to access your computer, install and run malicious software on your computer, or cause it to crash.

More technical information is available in US-CERT Technical Cyber Security Alert TA07-297A and Vulnerability Note VU#871673.


  • RealNetworks RealPlayer Security Update ->
  • Security Update for RealPlayer ->
  • US-CERT Technical Cyber Security Alert TA07-297A - <>
  • US-CERT Vulnerability Note VU#871673 ->
  • Securing Your Web Browser ->


Revision History

  • October 24, 2007: Initial release

This product is provided subject to this Notification and this Privacy & Use policy.

Please share your thoughts.

We recently updated our anonymous product survey; we'd welcome your feedback.