Lucene search

K
centosCentOS ProjectCESA-2005:517
HistoryJun 23, 2005 - 9:24 p.m.

HelixPlayer security update

2005-06-2321:24:53
CentOS Project
lists.centos.org
53

CVSS2

5.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

EPSS

0.799

Percentile

98.3%

CentOS Errata and Security Advisory CESA-2005:517

HelixPlayer is a media player.

A buffer overflow bug was found in the way HelixPlayer processes SMIL files.
An attacker could create a specially crafted SMIL file, which when combined
with a malicious web server, could execute arbitrary code when opened by a
user. The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-1766 to this issue.

All users of HelixPlayer are advised to upgrade to this updated package,
which contains HelixPlayer version 10.0.5 and is not vulnerable to this issue.

Merged security bulletin from advisories:
https://lists.centos.org/pipermail/centos-announce/2005-June/074061.html
https://lists.centos.org/pipermail/centos-announce/2005-June/074062.html

Affected packages:
HelixPlayer

Upstream details at:
https://access.redhat.com/errata/RHSA-2005:517

OSVersionArchitecturePackageVersionFilename
CentOS4i386helixplayer< 1.0.5-0.EL4.1HelixPlayer-1.0.5-0.EL4.1.i386.rpm
CentOS4i386helixplayer< 1.0.5-0.EL4.1HelixPlayer-1.0.5-0.EL4.1.i386.rpm

CVSS2

5.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

EPSS

0.799

Percentile

98.3%