NASLDB: RHSA-2008-0812: realplayer-uninstall
General
ID: 40726
Name: RHSA-2008-0812: realplayer-uninstall
Summary: Check for the version of the realplayer-uninstall packages
Credits: Tenable Network Security, Inc.
Classification
Risk: –
CVSS: –
CVSS Base Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C
CVSS Temporal Vector: –
Port: 0
Family: Red Hat Local Security Checks
Type: Local
Description
RealPlayer 10.0.9 as shipped in Red Hat Enterprise Linux 3 Extras, 4
Extras, and 5 Supplementary, contains a security flaw and should not be
used.
This update has been rated as having critical security impact by the Red
Hat Security Response Team.
[Updated 17 September 2008]
We have updated this erratum to include packages which remove RealPlayer
from Red Hat Enterprise Linux 3 Extras, 4 Extras and 5 Supplementary.
RealPlayer is a media player that provides media playback locally and via
streaming.
RealPlayer 10.0.9 is vulnerable to a critical security flaw and should no
longer be used. A remote attacker could leverage this flaw to execute
arbitrary code as the user running RealPlayer. (CVE-2007-5400)
This issue is addressed in RealPlayer 11. Red Hat is unable to ship
RealPlayer 11 due to additional proprietary codecs included in that
version. Therefore, users who wish to continue to use RealPlayer should get
an update directly from www.real.com.
This update removes the RealPlayer 10.0.9 packages due to their known
security vulnerabilities.
Exploiting
Exploit Available: –
Exploitability Ease: –
Sources
CVE: CVE-2007-5400
OSVDB: –
Bugtraq: –
scipID: –
Timeline
Vulnerability Disclosure: –
Patch Release: –
Plugin Release: 2009/08/24
Plugin
Version: 1.12
Filename: redhat-RHSA-2008-0812.nasl
Filesize: 3067 bytes
MD5 Hash: c4ee725b7e822ca994290300f269cc3c
Identification: Host/RedHat/rpm-list
Require Keys: Host/RedHat/rpm-list
Dependencies: "ssh_get_info.nasl"
Copyright: This script is Copyright© 2009-2012 Tenable Network Security, Inc.
- Letzte Plugins
- USN-1611-1 : thunderbird vulnerabilities
- USN-1610-1 : linux vulnerability
- USN-1609-1 : linux-ti-omap4 vulnerability
- SuSE 10 Security Update : PostgreSQL
- RHSA-2012-1364: bind97
- RHSA-2012-1363: bind
- RHSA-2012-1362: thunderbird
- RHSA-2012-1361: xulrunner
- Mandriva Linux Security Advisory : graphicsmagick
- FreeBSD : phpMyAdmin — Multiple XSS due to unescaped HTML output in Trigger, Procedure and Event pages and Fetching the version information from a non-SSL site is vulnerable to a MITM attack













