Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 53860 - media-video/realplayer, media-video/realone : more remote buffer overflows
Summary: media-video/realplayer, media-video/realone : more remote buffer overflows
Status: RESOLVED INVALID
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All All
: High enhancement (vote)
Assignee: Gentoo Security
URL: http://www.service.real.com/help/faq/...
Whiteboard: B2 [upstream masked]
Keywords:
Depends on:
Blocks:
 
Reported: 2004-06-13 23:23 UTC by Lance Albertson (RETIRED)
Modified: 2011-10-30 22:40 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Lance Albertson (RETIRED) gentoo-dev 2004-06-13 23:23:02 UTC
Excerpt from my SANS email:

04.23.27 CVE: Not Available
Platform: Cross Platform
Title: RealNetworks RealPlayer Remote Buffer Overflows
Description: RealPlayer is a media player for multiple operating
systems, including Windows, Linux and Mac OS. It has been reported
that multiple buffer overflows exist across multiple RealPlayer
software packages. RealNetworks has released multiple product updates
to remedy this issue.
Ref: http://www.service.real.com/help/faq/security/040610_player/EN/

The specific exploit were:

To fashion RAM files which corrupt the Player and which might allow an attacker to execute arbitrary code on a user's machine. Multiple issues were reported in this area.

I didn't see a specific link for Linux upgrades. They may not even have one.. who knows, but I figured it was worthy of a bug to at least be looked into.
Comment 1 Thierry Carrez (RETIRED) gentoo-dev 2004-06-15 04:06:03 UTC
Realplayer is currently masked for security reasons (bug #40469)
We are investigating whether the latest build we have is vulnerable to this (new) bug.
Comment 2 Vikram Dendi 2004-06-16 12:29:16 UTC
This bug does not affect RP8 for Linux or the new RP10 for Linux (which is in beta). Linux was not mentioned in the security fix release because it was not affected.
Comment 3 Thierry Carrez (RETIRED) gentoo-dev 2004-06-17 05:11:17 UTC
Thanks very much Vikram. Closing this one as INVALID.