NASLDB: RHSA-2005-394: realplayer
General
ID: 18111
Name: RHSA-2005-394: realplayer
Summary: Check for the version of the realplayer packages
Credits: Tenable Network Security, Inc.
Classification
Risk: –
CVSS: CVSS2#AV:N/AC:H/Au:N/C:P/I:P/A:P
CVSS Base Vector: –
CVSS Temporal Vector: –
Port: 0
Family: Red Hat Local Security Checks
Type: –
Description
An updated RealPlayer package that fixes a buffer overflow issue is now
available.
This update has been rated as having critical security impact by the Red
Hat Security Response Team.
RealPlayer is a media player providing solid media playback locally
and via streaming. It plays RealAudio, RealVideo, MP3, 3GPP Video,
Flash, SMIL 2.0, JPEG, GIF, PNG, RealPix and RealText and
more.
A buffer overflow bug was found in the way RealPlayer processes RAM files.
An attacker could create a specially crafted RAM file which could execute
arbitrary code when opened by a user. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CVE-2005-0755 to
this issue.
All users of RealPlayer are advised to upgrade to this updated package,
which contains RealPlayer version 10.0.4 and is not vulnerable to this
issue.
Exploiting
Exploit Available: –
Exploitability Ease: –
Sources
CVE: CVE-2005-0755
OSVDB: –
Bugtraq: –
scipID: –
Timeline
Vulnerability Disclosure: –
Patch Release: –
Plugin Release: 2005/04/21
Plugin
Version: 1.8
Filename: redhat-RHSA-2005-394.nasl
Filesize: 2328 bytes
MD5 Hash: b828c84de8acf8824b8a13b8780535fc
Identification: –
Require Keys: Host/RedHat/rpm-list
Dependencies: "ssh_get_info.nasl"
Copyright: This script is Copyright© 2005-2010 Tenable Network Security, Inc.
- Letzte Plugins
- USN-1611-1 : thunderbird vulnerabilities
- USN-1610-1 : linux vulnerability
- USN-1609-1 : linux-ti-omap4 vulnerability
- SuSE 10 Security Update : PostgreSQL
- RHSA-2012-1364: bind97
- RHSA-2012-1363: bind
- RHSA-2012-1362: thunderbird
- RHSA-2012-1361: xulrunner
- Mandriva Linux Security Advisory : graphicsmagick
- FreeBSD : phpMyAdmin — Multiple XSS due to unescaped HTML output in Trigger, Procedure and Event pages and Fetching the version information from a non-SSL site is vulnerable to a MITM attack













