Lucene search

K
osvGoogleOSV:DSA-826-1
HistorySep 29, 2005 - 12:00 a.m.

helix-player - multiple

2005-09-2900:00:00
Google
osv.dev
16

EPSS

0.968

Percentile

99.7%

Multiple security vulnerabilities have been identified in the
helix-player media player that could allow an attacker to execute code
on the victim’s machine via specially crafted network resources.

  • CAN-2005-1766
    Buffer overflow in the RealText parser could allow remote code
    execution via a specially crafted RealMedia file with a long
    RealText string.
  • CAN-2005-2710
    Format string vulnerability in Real HelixPlayer and RealPlayer 10
    allows remote attackers to execute arbitrary code via the image
    handle attribute in a RealPix (.rp) or RealText (.rt) file.

For the stable distribution (sarge), these problems have been fixed in
version 1.0.4-1sarge1

For the unstable distribution (sid), these problems have been fixed in
version 1.0.6-1

We recommend that you upgrade your helix-player package.

helix-player was distributed only on the i386 and powerpc architectures