Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 232997 (CVE-2007-5400) - media-video/realplayer <11.0.0.4028-r1 SWF file heap-based buffer overflow (CVE-2007-5400)
Summary: media-video/realplayer <11.0.0.4028-r1 SWF file heap-based buffer overflow (C...
Status: RESOLVED FIXED
Alias: CVE-2007-5400
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL: http://service.real.com/realplayer/se...
Whiteboard: B2 [glsa]
Keywords:
Depends on: 235777
Blocks:
  Show dependency tree
 
Reported: 2008-07-26 15:04 UTC by Carsten Lohrke (RETIRED)
Modified: 2008-10-17 07:52 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Carsten Lohrke (RETIRED) gentoo-dev 2008-07-26 15:04:42 UTC
SWF file heap-based buffer overflow
Comment 1 Steve Dibb (RETIRED) gentoo-dev 2008-07-29 01:50:51 UTC
Realplayer 11 was masked for testing.  Never heard a peep though, so I just unmasked it.
Comment 2 denis 2008-07-29 14:29:50 UTC
(In reply to comment #1)
> Realplayer 11 was masked for testing.  Never heard a peep though, so I just
> unmasked it.
> 

Hi. reaplay and realplay.bin were not set executable. I had to chmod x them.
Comment 3 Robert Buchholz (RETIRED) gentoo-dev 2008-08-05 01:37:15 UTC
ping, video team.
Comment 4 Matthias Schwarzott gentoo-dev 2008-08-08 17:43:20 UTC
(In reply to comment #2)
> 
> Hi. reaplay and realplay.bin were not set executable. I had to chmod x them.
> 
This is fixed. See Bug #233415.

(In reply to comment #3)
@rbu: What should we do?
Comment 5 Pierre-Yves Rofes (RETIRED) gentoo-dev 2008-08-09 21:53:02 UTC
is fixed. See Bug #233415.
> 
> (In reply to comment #3)
> @rbu: What should we do?
> 
since the vulnerable version (0.10.9) had stable keywords, we'll need a fixed version with stable keywords too. Is realplayer-11.0.0.4028-r1 ready to go stable? If so, feel free to CC arches on this bug for stabilisation.

Comment 6 Robert Buchholz (RETIRED) gentoo-dev 2008-08-14 10:53:34 UTC
Please let us know whether you consider the ebuild ready for stabling.
Comment 7 Robert Buchholz (RETIRED) gentoo-dev 2008-08-15 14:31:48 UTC
Arches, please test and mark stable:
=media-video/realplayer-11.0.0.4028-r1
Target keywords : "amd64 x86"
Comment 8 Markus Meier gentoo-dev 2008-08-15 18:15:25 UTC
amd64/x86 stable, all arches done.
Comment 9 Mathieu Z 2008-08-25 23:26:23 UTC
RealPlayer-11.0.0.4028-r1 wouldn't unpack:

>>> Unpacking source...
>>> Unpacking RealPlayer11GOLD.rpm to /var/tmp/portage/media-video/realplayer-11.0.0.4028-r1/work
 *
 * ERROR: media-video/realplayer-11.0.0.4028-r1 failed.
 * Call stack:
 *               ebuild.sh, line   49:  Called src_unpack
 *             environment, line 2177:  Called rpm_src_unpack
 *             environment, line 2044:  Called die
 * The specific snippet of code:
 *                   rpm_unpack ${DISTDIR}/${x} || die "${myfail}";
 *  The die message:
 *   failure unpacking RealPlayer11GOLD.rpm
 *
 * If you need support, post the topmost build error, and the call stack if relevant.
 * A complete build log is located at '/var/log/portage/media-video:realplayer-11.0.0.4028-r1:20080825-232153.log'.
 * The ebuild environment file is located at '/var/tmp/portage/media-video/realplayer-11.0.0.4028-r1/temp/environment'.
 *
Comment 10 Robert Buchholz (RETIRED) gentoo-dev 2008-08-26 00:35:13 UTC
Matthew, please open a new bug for that and mark it as a blocker of this bug. Please attach the full build log, and your emerge --info.
Comment 11 Paulo J. Matos 2008-08-28 08:29:43 UTC
Same problem here with rpm_unpack.
Comment 12 Robert Buchholz (RETIRED) gentoo-dev 2008-09-04 20:12:21 UTC
GLSA 200809-03
Comment 13 walt 2008-09-15 12:53:32 UTC
** (realplay.bin:18835): CRITICAL **: file superbufhscale.cpp: line 493 (void hx_superbuf_hscale_init(HXSuperbufHScale*)): assertion `superbuf_hscale->tile_graphics[HX_SUPERB_MODE_BG].pixbuf' failed
** (realplay.bin:18835): WARNING **: HXPlayer: Error 0x80004005: "A general error has occurred."

This is what I see when running the stable 32-bit version on an amd64 machine.
The same machine will run a 64-bit nightly build from helix, however.
No one else seeing this?
Comment 14 Peter Volkov (RETIRED) gentoo-dev 2008-10-17 07:52:05 UTC
(In reply to comment #13)
> ** (realplay.bin:18835): CRITICAL **: file superbufhscale.cpp: line 499 ...

Please, open new bug. This bug is fixed ;)