RealNetworks RealPlayer And Helix Player Format String Vulnerability
BID:14945
Info
RealNetworks RealPlayer And Helix Player Format String Vulnerability
| Bugtraq ID: | 14945 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-2710 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 26 2005 12:00AM |
| Updated: | Jul 12 2009 05:06PM |
| Credit: | iDEFENSE Labs discovered this vulnerability. |
| Vulnerable: |
S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Professional 9.2 x86_64 S.u.S.E. Linux Professional 9.2 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 Redhat Fedora Core4 Redhat Fedora Core3 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux AS 4 Redhat Desktop 4.0 RealNetworks RealPlayer For Unix 10.0.4 RealNetworks RealPlayer For Unix 10.0.3 RealNetworks RealPlayer 10 for Linux RealNetworks RealPlayer 10 Japanese RealNetworks RealPlayer 10 German RealNetworks RealPlayer 10 English RealNetworks Helix Player for Linux 1.0.5 RealNetworks Helix Player for Linux 1.0.4 RealNetworks Helix Player for Linux 1.0.3 RealNetworks Helix Player for Linux 1.0.2 RealNetworks Helix Player for Linux 1.0.1 RealNetworks Helix Player for Linux 1.0 |
| Not Vulnerable: | |
Discussion
RealNetworks RealPlayer And Helix Player Format String Vulnerability
RealPlayer and Helix player are susceptible to a format string vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied input, allowing a remote attacker to supply format specifiers directly to a formatted printing function.
Successful exploitation of this vulnerability allows remote attackers to execute arbitrary machine code in the context of the affected application.
RealPlayer 10.0 through 10.0.5 for Linux and Helix Player 1.0 through 1.0.5 are prone to this issue.
RealPlayer and Helix player are susceptible to a format string vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied input, allowing a remote attacker to supply format specifiers directly to a formatted printing function.
Successful exploitation of this vulnerability allows remote attackers to execute arbitrary machine code in the context of the affected application.
RealPlayer 10.0 through 10.0.5 for Linux and Helix Player 1.0 through 1.0.5 are prone to this issue.
Exploit / POC
RealNetworks RealPlayer And Helix Player Format String Vulnerability
An exploit was provided by c0ntex <[email protected]>:
An exploit was provided by c0ntex <[email protected]>:
Solution / Fix
RealNetworks RealPlayer And Helix Player Format String Vulnerability
Solution:
RedHat has released advisories RHSA-2005:788-3, FEDORA-2005-940, and FEDORA-2005-941 to address this issue in RedHat Enterprise Linux, and Fedora Core 3 and 4 respectively. Please see the referenced advisories for further information.
Debian has released advisory DSA 826-1 to address this issue. Please see the attached advisory for details on obtaining and applying fixes.
Gentoo has released advisory GLSA 200510-07 to address this issue.
Gentoo users may obtain RealPlayer updates by running the following commands as the superuser:
emerge --sync
emerge --ask --oneshot --verbose ">=media-video/realplayer-10.0.6"
Gentoo users may obtain Helix Player updates by running the following commands as the superuser:
emerge --sync
emerge --ask --oneshot --verbose ">=media-video/helixplayer-1.0.6"
SUSE has released advisory SUSE-SA:2005:059 to address this issue in affected products. Please see the referenced advisory for more information.
RealNetworks has released fixes for this issue:
RealNetworks RealPlayer 10 for Linux
RealNetworks Helix Player for Linux 1.0
RealNetworks Helix Player for Linux 1.0.1
RealNetworks Helix Player for Linux 1.0.2
RealNetworks Helix Player for Linux 1.0.3
RealNetworks Helix Player for Linux 1.0.4
RealNetworks Helix Player for Linux 1.0.5
Solution:
RedHat has released advisories RHSA-2005:788-3, FEDORA-2005-940, and FEDORA-2005-941 to address this issue in RedHat Enterprise Linux, and Fedora Core 3 and 4 respectively. Please see the referenced advisories for further information.
Debian has released advisory DSA 826-1 to address this issue. Please see the attached advisory for details on obtaining and applying fixes.
Gentoo has released advisory GLSA 200510-07 to address this issue.
Gentoo users may obtain RealPlayer updates by running the following commands as the superuser:
emerge --sync
emerge --ask --oneshot --verbose ">=media-video/realplayer-10.0.6"
Gentoo users may obtain Helix Player updates by running the following commands as the superuser:
emerge --sync
emerge --ask --oneshot --verbose ">=media-video/helixplayer-1.0.6"
SUSE has released advisory SUSE-SA:2005:059 to address this issue in affected products. Please see the referenced advisory for more information.
RealNetworks has released fixes for this issue:
RealNetworks RealPlayer 10 for Linux
-
Real Networks RealPlayer 10 for Linux
http://www.real.com/realcom/R?href=http%3A%2F%2Fforms.real.com%2Freal% 2Fplayer%2Fdownload.html%3Ff%3Dunix%2FRealPlayer10GOLD.bin%26product%3 Dplayerplus%26system%3Dlinux%26pcode%3Drn%26src%3Dlinux%26opage%3Dlinu x&pageid=linuxPage&pageregion=offer_button -
SUSE RealPlayer-10.0.6-1.4.i586.rpm
SUSE LINUX 10.0:
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/i586/RealPlayer-10.0.6 -1.4.i586.rpm -
SUSE RealPlayer-10.0.6-1.4.i586.rpm
SUSE LINUX 10.0:
ftp://ftp.suse.com/pub/suse/i386/update/9.3/rpm/i586/RealPlayer-10.0.6 -1.4.i586.rpm -
SUSE RealPlayer-10.0.6-3.2.i586.rpm
SUSE LINUX 10.0:
ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/i586/RealPlayer-10.0. 6-3.2.i586.rpm
RealNetworks Helix Player for Linux 1.0
-
Real Networks Helix Player 1.0.6 Gold
https://player.helixcommunity.org/2005/downloads/
RealNetworks Helix Player for Linux 1.0.1
-
Real Networks Helix Player 1.0.6 Gold
https://player.helixcommunity.org/2005/downloads/
RealNetworks Helix Player for Linux 1.0.2
-
Real Networks Helix Player 1.0.6 Gold
https://player.helixcommunity.org/2005/downloads/
RealNetworks Helix Player for Linux 1.0.3
-
Real Networks Helix Player 1.0.6 Gold
https://player.helixcommunity.org/2005/downloads/
RealNetworks Helix Player for Linux 1.0.4
-
Debian helix-player_1.0.4-1sarge1_i386.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/h/helix-player/helix-play er_1.0.4-1sarge1_i386.deb -
Debian helix-player_1.0.4-1sarge1_powerpc.deb
http://security.debian.org/pool/updates/main/h/helix-player/helix-play er_1.0.4-1sarge1_powerpc.deb -
Real Networks Helix Player 1.0.6 Gold
https://player.helixcommunity.org/2005/downloads/ -
RedHat Fedora HelixPlayer-1.0.6-1.fc4.2.i386.rpm
Fedora Core 4
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/ -
RedHat Fedora HelixPlayer-1.0.6-1.fc4.2.ppc.rpm
Fedora Core 4
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/ -
RedHat Fedora HelixPlayer-debuginfo-1.0.6-1.fc4.2.i386.rpm
Fedora Core 4
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/ -
RedHat Fedora HelixPlayer-debuginfo-1.0.6-1.fc4.2.ppc.rpm
Fedora Core 4
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/
RealNetworks Helix Player for Linux 1.0.5
-
Real Networks Helix Player 1.0.6 Gold
https://player.helixcommunity.org/2005/downloads/
References
RealNetworks RealPlayer And Helix Player Format String Vulnerability
References:
References:
- Helix Player Home Page (Real Networks)
- RealNetworks, Inc. Releases Update to Address Security Vulnerabilities. (Real Networks)
- RealPlayer Homepage (Real Networks)
- RHSA-2005:788-3 - HelixPlayer security update (RedHat)
- iDEFENSE Security Advisory 09.30.05: RealNetworks RealPlayer/HelixPlayer RealPix ("iDEFENSE Labs"
)