An updated RealPlayer package that fixes a buffer overflow issue is now
available.
This update has been rated as having critical security impact by the Red
Hat Security Response Team.
[Updated 05 Jul 2005]
The previous package for Red Hat Enterprise Linux 4 did not contain the
proper fix for this issue. This erratum has been updated with a replacement
package that corrects this issue
RealPlayer is a media player that provides media playback locally and
via streaming. It plays RealAudio, RealVideo, MP3, 3GPP Video, Flash, SMIL
2.0, JPEG, GIF, PNG, RealPix, RealText, and more.
A buffer overflow bug was found in the way RealPlayer processes SMIL files.
An attacker could create a specially crafted SMIL file that could combine
with a malicious Web server to execute arbitrary code when the file was
opened by a user. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-1766 to this issue.
All users of RealPlayer are advised to upgrade to this updated package,
which contains RealPlayer version 10.0.5 and is not vulnerable to this issue.
| Red Hat Enterprise Linux Extras (v. 3) |
|
| IA-32: |
realplayer-10.0.5-0.rhel3.1.i386.rpm
File outdated by: RHSA-2007:0841 |
7508c3d3ca7a7739e3422ad14537b657 |
realplayer-10.0.5-0.rhel3.1.i386.rpm
File outdated by: RHSA-2007:0841 |
7508c3d3ca7a7739e3422ad14537b657 |
realplayer-10.0.5-0.rhel3.1.i386.rpm
File outdated by: RHSA-2007:0841 |
7508c3d3ca7a7739e3422ad14537b657 |
realplayer-10.0.5-0.rhel3.1.i386.rpm
File outdated by: RHSA-2007:0841 |
7508c3d3ca7a7739e3422ad14537b657 |
| |
| x86_64: |
realplayer-10.0.5-0.rhel3.1.i386.rpm
File outdated by: RHSA-2007:0841 |
7508c3d3ca7a7739e3422ad14537b657 |
realplayer-10.0.5-0.rhel3.1.i386.rpm
File outdated by: RHSA-2007:0841 |
7508c3d3ca7a7739e3422ad14537b657 |
realplayer-10.0.5-0.rhel3.1.i386.rpm
File outdated by: RHSA-2007:0841 |
7508c3d3ca7a7739e3422ad14537b657 |
realplayer-10.0.5-0.rhel3.1.i386.rpm
File outdated by: RHSA-2007:0841 |
7508c3d3ca7a7739e3422ad14537b657 |
| |
| Red Hat Enterprise Linux Extras (v. 4) |
|
| IA-32: |
RealPlayer-10.0.5-2.i386.rpm
File outdated by: RHSA-2007:0841 |
4d71e816c48c03236ac6653b343daf77 |
RealPlayer-10.0.5-2.i386.rpm
File outdated by: RHSA-2007:0841 |
4d71e816c48c03236ac6653b343daf77 |
RealPlayer-10.0.5-2.i386.rpm
File outdated by: RHSA-2007:0841 |
4d71e816c48c03236ac6653b343daf77 |
RealPlayer-10.0.5-2.i386.rpm
File outdated by: RHSA-2007:0841 |
4d71e816c48c03236ac6653b343daf77 |
| |
| x86_64: |
RealPlayer-10.0.5-2.i386.rpm
File outdated by: RHSA-2007:0841 |
4d71e816c48c03236ac6653b343daf77 |
RealPlayer-10.0.5-2.i386.rpm
File outdated by: RHSA-2007:0841 |
4d71e816c48c03236ac6653b343daf77 |
RealPlayer-10.0.5-2.i386.rpm
File outdated by: RHSA-2007:0841 |
4d71e816c48c03236ac6653b343daf77 |
RealPlayer-10.0.5-2.i386.rpm
File outdated by: RHSA-2007:0841 |
4d71e816c48c03236ac6653b343daf77 |
| |
(The unlinked packages above are only available from the Red Hat Network)
|
159864 - CAN-2005-1766 RealPlayer heap overflow
159868 - CAN-2005-1766 RealPlayer heap overflow