RealNetworks RealPlayer And Helix Player Format String Vulnerability

BID:14945

Info

RealNetworks RealPlayer And Helix Player Format String Vulnerability

Bugtraq ID: 14945
Class: Input Validation Error
CVE: CVE-2005-2710
Remote: Yes
Local: No
Published: Sep 26 2005 12:00AM
Updated: Jul 12 2009 05:06PM
Credit: iDEFENSE Labs discovered this vulnerability.
Vulnerable: S.u.S.E. Novell Linux Desktop 9.0
S.u.S.E. Linux Professional 10.0 OSS
S.u.S.E. Linux Professional 10.0
S.u.S.E. Linux Professional 9.3 x86_64
S.u.S.E. Linux Professional 9.3
S.u.S.E. Linux Professional 9.2 x86_64
S.u.S.E. Linux Professional 9.2
S.u.S.E. Linux Personal 10.0 OSS
S.u.S.E. Linux Personal 9.3 x86_64
S.u.S.E. Linux Personal 9.3
S.u.S.E. Linux Personal 9.2 x86_64
S.u.S.E. Linux Personal 9.2
Redhat Fedora Core4
Redhat Fedora Core3
Redhat Enterprise Linux WS 4
Redhat Enterprise Linux ES 4
Redhat Enterprise Linux AS 4
Redhat Desktop 4.0
RealNetworks RealPlayer For Unix 10.0.4
+ Redhat Enterprise Linux AS 4
+ Redhat Enterprise Linux ES 4
+ Redhat Enterprise Linux WS 4
+ S.u.S.E. Linux Personal 9.3
+ S.u.S.E. Linux Personal 9.2
RealNetworks RealPlayer For Unix 10.0.3
+ S.u.S.E. Linux Personal 9.3
+ S.u.S.E. Linux Personal 9.2
RealNetworks RealPlayer 10 for Linux
RealNetworks RealPlayer 10 Japanese
RealNetworks RealPlayer 10 German
RealNetworks RealPlayer 10 English
RealNetworks Helix Player for Linux 1.0.5
+ Gentoo Linux
RealNetworks Helix Player for Linux 1.0.4
+ Debian Linux 3.1 sparc
+ Debian Linux 3.1 s/390
+ Debian Linux 3.1 ppc
+ Debian Linux 3.1 mipsel
+ Debian Linux 3.1 mips
+ Debian Linux 3.1 m68k
+ Debian Linux 3.1 ia-64
+ Debian Linux 3.1 ia-32
+ Debian Linux 3.1 hppa
+ Debian Linux 3.1 arm
+ Debian Linux 3.1 amd64
+ Debian Linux 3.1 alpha
+ Debian Linux 3.1
+ Redhat Desktop 4.0
+ Redhat Enterprise Linux AS 4
+ Redhat Enterprise Linux ES 4
+ Redhat Enterprise Linux WS 4
+ Redhat Fedora Core3
RealNetworks Helix Player for Linux 1.0.3
+ Gentoo Linux
+ Redhat Fedora Core3
RealNetworks Helix Player for Linux 1.0.2
+ Redhat Enterprise Linux AS 4
+ Redhat Enterprise Linux ES 4
+ Redhat Enterprise Linux WS 4
RealNetworks Helix Player for Linux 1.0.1
RealNetworks Helix Player for Linux 1.0
Not Vulnerable:

Discussion

RealNetworks RealPlayer And Helix Player Format String Vulnerability

RealPlayer and Helix player are susceptible to a format string vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied input, allowing a remote attacker to supply format specifiers directly to a formatted printing function.

Successful exploitation of this vulnerability allows remote attackers to execute arbitrary machine code in the context of the affected application.

RealPlayer 10.0 through 10.0.5 for Linux and Helix Player 1.0 through 1.0.5 are prone to this issue.

Exploit / POC

RealNetworks RealPlayer And Helix Player Format String Vulnerability

An exploit was provided by c0ntex <[email protected]>:

Solution / Fix

RealNetworks RealPlayer And Helix Player Format String Vulnerability

Solution:
RedHat has released advisories RHSA-2005:788-3, FEDORA-2005-940, and FEDORA-2005-941 to address this issue in RedHat Enterprise Linux, and Fedora Core 3 and 4 respectively. Please see the referenced advisories for further information.

Debian has released advisory DSA 826-1 to address this issue. Please see the attached advisory for details on obtaining and applying fixes.

Gentoo has released advisory GLSA 200510-07 to address this issue.

Gentoo users may obtain RealPlayer updates by running the following commands as the superuser:

emerge --sync
emerge --ask --oneshot --verbose ">=media-video/realplayer-10.0.6"

Gentoo users may obtain Helix Player updates by running the following commands as the superuser:

emerge --sync
emerge --ask --oneshot --verbose ">=media-video/helixplayer-1.0.6"

SUSE has released advisory SUSE-SA:2005:059 to address this issue in affected products. Please see the referenced advisory for more information.

RealNetworks has released fixes for this issue:


RealNetworks RealPlayer 10 for Linux

RealNetworks Helix Player for Linux 1.0

RealNetworks Helix Player for Linux 1.0.1

RealNetworks Helix Player for Linux 1.0.2

RealNetworks Helix Player for Linux 1.0.3

RealNetworks Helix Player for Linux 1.0.4

RealNetworks Helix Player for Linux 1.0.5

References

RealNetworks RealPlayer And Helix Player Format String Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report