| PROBLEM: | A buffer overflow bug was discovered in the way RealPlayer processes Flash Media (.swf) files. |
| PLATFORM: | Red Hat Enterprise Linux Extras (v. 3, 4) |
| DAMAGE: | It is possible for a malformed Flash Media file to execute arbitrary code as the user running RealPlayer. |
| SOLUTION: | Apply current patches. |
| VULNERABILITY ASSESSMENT: |
The risk is MEDIUM. Execution of arbitrary code. |
| LINKS: | |
| CIAC BULLETIN: | http://www.ciac.org/ciac/bulletins/q-153.shtml |
| ORIGINAL BULLETIN: | http://rhn.redhat.com/errata/RHSA-2006-0257.html |
| CVE: | CVE-2006-0323 |
[***** Start RHSA-2006:0257-9 *****]
| Advisory: | RHSA-2006:0257-9 |
|---|---|
| Type: | Security Advisory |
| Issued on: | 2006-03-22 |
| Last updated on: | 2006-03-22 |
| Affected Products: | Red Hat Enterprise Linux Extras (v. 3) Red Hat Enterprise Linux Extras (v. 4) |
| CVEs (cve.mitre.org): | CVE-2006-0323 |
An updated RealPlayer package that fixes a buffer overflow bug is now
available for Red Hat Enterprise Linux Extras 3 and 4.
This update has been rated as having critical security impact by the Red
Hat Security Response Team.
RealPlayer is a media player that provides media playback locally and via
streaming.
A buffer overflow bug was discovered in the way RealPlayer processes Flash
Media (.swf) files. It is possible for a malformed Flash Media file to
execute arbitrary code as the user running RealPlayer. The Common
Vulnerabilities and Exposures project assigned the name CVE-2006-0323 to
this issue.
All users of RealPlayer are advised to upgrade to this updated package,
which contains RealPlayer version 10.0.7 and is not vulnerable to this issue.
| Red Hat Enterprise Linux Extras (v. 3) | |
| IA-32: | |
| realplayer-10.0.7-0.rhel3.2.i386.rpm | 9d1833768d49eacd7e96e107867a440d |
| realplayer-10.0.7-0.rhel3.2.i386.rpm | 9d1833768d49eacd7e96e107867a440d |
| realplayer-10.0.7-0.rhel3.2.i386.rpm | 9d1833768d49eacd7e96e107867a440d |
| realplayer-10.0.7-0.rhel3.2.i386.rpm | 9d1833768d49eacd7e96e107867a440d |
| x86_64: | |
| realplayer-10.0.7-0.rhel3.2.i386.rpm | 9d1833768d49eacd7e96e107867a440d |
| realplayer-10.0.7-0.rhel3.2.i386.rpm | 9d1833768d49eacd7e96e107867a440d |
| realplayer-10.0.7-0.rhel3.2.i386.rpm | 9d1833768d49eacd7e96e107867a440d |
| realplayer-10.0.7-0.rhel3.2.i386.rpm | 9d1833768d49eacd7e96e107867a440d |
| Red Hat Enterprise Linux Extras (v. 4) | |
| IA-32: | |
| RealPlayer-10.0.7-2.i386.rpm | c13c039a758626a17e5030d3108642a0 |
| RealPlayer-10.0.7-2.i386.rpm | c13c039a758626a17e5030d3108642a0 |
| RealPlayer-10.0.7-2.i386.rpm | c13c039a758626a17e5030d3108642a0 |
| RealPlayer-10.0.7-2.i386.rpm | c13c039a758626a17e5030d3108642a0 |
| x86_64: | |
| RealPlayer-10.0.7-2.i386.rpm | c13c039a758626a17e5030d3108642a0 |
| RealPlayer-10.0.7-2.i386.rpm | c13c039a758626a17e5030d3108642a0 |
| RealPlayer-10.0.7-2.i386.rpm | c13c039a758626a17e5030d3108642a0 |
| RealPlayer-10.0.7-2.i386.rpm | c13c039a758626a17e5030d3108642a0 |
| (The unlinked packages above are only available from the Red Hat Network) |
|
183932 - CVE-2006-0323 RealPlayer SWF file buffer overflow
The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/
[***** End RHSA-2006:0257-9 *****]
Voice: +1 866-941-2472 (7 x 24)
E-mail: doecirc@doecirc.energy.gov
World Wide Web: http://www.doecirc.energy.gov/