CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS
Percentile
99.7%
CentOS Errata and Security Advisory CESA-2005:788
HelixPlayer is a media player.
A format string bug was discovered in the way HelixPlayer processes RealPix
(.rp) files. It is possible for a malformed RealPix file to execute
arbitrary code as the user running HelixPlayer. The Common Vulnerabilities
and Exposures project (cve.mitre.org) has assigned the name CAN-2005-2710
to this issue.
All users of HelixPlayer are advised to upgrade to this updated package,
which contains HelixPlayer version 10.0.6 and is not vulnerable to this issue.
Merged security bulletin from advisories:
https://lists.centos.org/pipermail/centos-announce/2005-September/074369.html
https://lists.centos.org/pipermail/centos-announce/2005-September/074370.html
Affected packages:
HelixPlayer
Upstream details at:
https://access.redhat.com/errata/RHSA-2005:788
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
CentOS | 4 | i386 | helixplayer | < 1.0.6-0.EL4.1 | HelixPlayer-1.0.6-0.EL4.1.i386.rpm |
CentOS | 4 | i386 | helixplayer | < 1.0.6-0.EL4.1 | HelixPlayer-1.0.6-0.EL4.1.i386.rpm |