Bug 96923 - media-video/{helix|real}player heap overflow
Bug#: 96923 Product:  Gentoo Security Version: unspecified Platform: All
OS/Version: Other Status: RESOLVED Severity: major Priority: P2
Resolution: FIXED Assigned To: security@gentoo.org Reported By: jaervosz@gentoo.org
Component: Vulnerabilities
URL:  http://service.real.com/help/faq/security/050623_player/EN/
Summary: media-video/{helix|real}player heap overflow
Keywords:  
Status Whiteboard: A2 [glsa] jaervosz
Opened: 2005-06-23 23:18 0000
Description:   Opened: 2005-06-23 23:18 0000
A vulnerability exists when handling RealText that can result in a heap
overflow.

------- Comment #1 From Thierry Carrez (RETIRED) 2005-06-24 01:18:15 0000 -------
Upgrade to realplayer-10.0.5 and helixplayer-1.0.5 is necessary.

------- Comment #2 From Diego E. 'Flameeyes' Pettenò 2005-06-24 04:22:46 0000 -------
It doesn't seems to be released yet (also if Real's security advisory states 
else). 
 

------- Comment #3 From Diego E. 'Flameeyes' Pettenò 2005-06-24 15:09:29 0000 -------
Ok committed 1.0.5 and 10.0.5. Little problem: I can't test helixplayer here 
as it's x86-only so I dropped the keywords until someone can test it. 
 

------- Comment #4 From Sune Kloppenborg Jeppesen 2005-06-24 15:30:46 0000 -------
Thx Diego, 
 
x86 please test and mark   
helixplayer-1.0.5 ~x86  
realplayer-10.0.5 x86  

------- Comment #5 From Thierry Carrez (RETIRED) 2005-06-27 01:19:20 0000 -------
x86 testing: see above comment.

------- Comment #6 From Sune Kloppenborg Jeppesen 2005-07-05 01:55:32 0000 -------
x86/someone please test and mark stable ASAP.  

------- Comment #7 From John Mylchreest (RETIRED) 2005-07-06 03:04:45 0000 -------
marked ~x86

------- Comment #8 From Henrik Brix Andersen 2005-07-06 04:40:42 0000 -------
Tested realplayer-10.0.5 and marked stable on x86 on request from jaervosz.

------- Comment #9 From Thierry Carrez (RETIRED) 2005-07-06 05:52:14 0000 -------
Thx everyone, ready for GLSA

------- Comment #10 From Thierry Carrez (RETIRED) 2005-07-06 06:51:24 0000 -------
GLSA 200507-04