Helix Player RuleBook Structure Heap Buffer Overflow Vulnerability
BID:38160
Info
Helix Player RuleBook Structure Heap Buffer Overflow Vulnerability
| Bugtraq ID: | 38160 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2010-0417 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 14 2008 12:00AM |
| Updated: | Jan 14 2008 12:00AM |
| Credit: | stanb |
| Vulnerable: |
Redhat Enterprise Linux WS 4 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux AS 4 Redhat Enterprise Linux Desktop version 4 RealNetworks Helix Player for Linux 11.0.2 RealNetworks Helix Player for Linux 11.0.1 RealNetworks Helix Player for Linux 11.0 RealNetworks Helix Player for Linux 10.0.7 RealNetworks Helix Player for Linux 10.0.6 RealNetworks Helix Player for Linux 10.0.5 RealNetworks Helix Player for Linux 10.0.4 RealNetworks Helix Player for Linux 10.0.3 RealNetworks Helix Player for Linux 10.0.2 RealNetworks Helix Player for Linux 10.0.1 RealNetworks Helix Player for Linux 10.0 |
| Not Vulnerable: | |
Discussion
Helix Player RuleBook Structure Heap Buffer Overflow Vulnerability
Helix Player is prone to a heap-based buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied input.
Successful exploits may allow remote attackers to execute arbitrary code in the context of the application. Failed exploit attempts will cause denial-of-service conditions.
Helix Player is prone to a heap-based buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied input.
Successful exploits may allow remote attackers to execute arbitrary code in the context of the application. Failed exploit attempts will cause denial-of-service conditions.
Exploit / POC
Helix Player RuleBook Structure Heap Buffer Overflow Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Helix Player RuleBook Structure Heap Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
Helix Player RuleBook Structure Heap Buffer Overflow Vulnerability
References:
References:
- [Common-cvs] util rlstate.cpp,1.9,1.10 (stanb)
- Bug 561860 �?? CVE-2010-0417 HelixPlayer / RealPlayer: rule book handling heap cor (Tomas Hoger)
- Helix Player Homepage (Real Networks)