<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>183421</bug_id>
          
          <creation_ts>2007-06-27 15:48 0000</creation_ts>
          <short_desc>media-video/realplayer - stack overflow vulnerability (CVE-2007-3410)</short_desc>
          <delta_ts>2007-09-14 21:45:22 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=547</bug_file_loc>
          <status_whiteboard>B2 [glsa] p-y</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>carlo@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>marktrolley@gmail.com</cc>
    
    <cc>media-video@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>carlo@gentoo.org</who>
            <bug_when>2007-06-27 15:48:28 0000</bug_when>
            <thetext>Remote exploitation of a buffer overflow within RealNetworks&apos; RealPlayer and HelixPlayer allows attackers to execute arbitrary code in the context of the user.

The issue specifically exists in the handling of HH:mm:ss.f time formats by the &apos;wallclock&apos; functionality within the code supporting SMIL2. An excerpt from the code follows.


http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=547</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>py@gentoo.org</who>
            <bug_when>2007-07-15 15:21:00 0000</bug_when>
            <thetext>media-video, what&apos;s the status here? please advise.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>beandog@gentoo.org</who>
            <bug_when>2007-07-15 16:00:10 0000</bug_when>
            <thetext>I haven&apos;t seen any releases from usptream regarding the issue, I&apos;ll have to find out what the status is.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jakub@gentoo.org</who>
            <bug_when>2007-08-17 06:35:28 0000</bug_when>
            <thetext>*** Bug 189190 has been marked as a duplicate of this bug. ***</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jakub@gentoo.org</who>
            <bug_when>2007-08-17 06:37:09 0000</bug_when>
            <thetext>https://player.helixcommunity.org/2007/releases/rp10gold/RP10_0_9ReleaseNotes.html

What&apos;s New in 10.0.9

    * This is a security update with a piggy-back bug fix.
    * Fixed an embedded player crash in some music web sites.

No idea if this fixes this one, the above is all they provide. The damned thing is again not downloadable via normal SRC_URI, suggest that we finally stick RESTRICT=fetch into the ebuild and are done with it.

https://helixcommunity.org/projects/player/files/download/2479</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-08-17 21:40:54 0000</bug_when>
            <thetext>media-video does 10.0.9 solve the current issue?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>beandog@gentoo.org</who>
            <bug_when>2007-08-25 14:02:51 0000</bug_when>
            <thetext>media-video/realplayer-10.0.9 in the tree</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>arfrever@gentoo.org</who>
            <bug_when>2007-08-26 13:30:17 0000</bug_when>
            <thetext>(In reply to comment #6)
&gt; media-video/realplayer-10.0.9 in the tree

Now there is such a message:
 * Download RealPlayer manually from Real&apos;s website at
 *
 *

Please replace ${DOWNLOADPAGE} with ${HOMEPAGE}.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>beandog@gentoo.org</who>
            <bug_when>2007-08-27 13:45:05 0000</bug_when>
            <thetext>(In reply to comment #7)
&gt; (In reply to comment #6)
&gt; &gt; media-video/realplayer-10.0.9 in the tree
&gt; 
&gt; Now there is such a message:
&gt;  * Download RealPlayer manually from Real&apos;s website at
&gt;  *
&gt;  *
&gt; 
&gt; Please replace ${DOWNLOADPAGE} with ${HOMEPAGE}.
&gt; 

fixed, thanks

</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-08-28 19:48:09 0000</bug_when>
            <thetext>x86 please test and mark stable.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jurek@gentoo.org</who>
            <bug_when>2007-08-28 22:25:14 0000</bug_when>
            <thetext>x86 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>py@gentoo.org</who>
            <bug_when>2007-08-29 10:20:18 0000</bug_when>
            <thetext>glsa request filed.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>falco@gentoo.org</who>
            <bug_when>2007-09-14 21:45:22 0000</bug_when>
            <thetext>it&apos;s GLSA 200709-05, thanks everybody</thetext>
          </long_desc>
      
    </bug>

</bugzilla>