Rapid7 Vulnerability & Exploit Database

RHSA-2010:0094: HelixPlayer security update

Back to Search

RHSA-2010:0094: HelixPlayer security update

Severity
9
CVSS
(AV:N/AC:M/Au:N/C:C/I:C/A:C)
Published
01/25/2010
Created
07/25/2018
Added
02/11/2010
Modified
07/04/2017

Description

HelixPlayer is a media player.Multiple buffer and integer overflow flaws were found in the wayHelixPlayer processed Graphics Interchange Format (GIF) files. An attackercould create a specially-crafted GIF file which would cause HelixPlayer tocrash or, potentially, execute arbitrary code when opened. (CVE-2009-4242,CVE-2009-4245)A buffer overflow flaw was found in the way HelixPlayer processedSynchronized Multimedia Integration Language (SMIL) files. An attackercould create a specially-crafted SMIL file which would cause HelixPlayer tocrash or, potentially, execute arbitrary code when opened. (CVE-2009-4257)A buffer overflow flaw was found in the way HelixPlayer handled the RealTime Streaming Protocol (RTSP) SET_PARAMETER directive. A malicious RTSPserver could use this flaw to crash HelixPlayer or, potentially, executearbitrary code. (CVE-2009-4248)Multiple buffer overflow flaws were discovered in the way HelixPlayerhandled RuleBook structures in media files and RTSP streams.Specially-crafted input could cause HelixPlayer to crash or, potentially,execute arbitrary code. (CVE-2009-4247, CVE-2010-0417)A buffer overflow flaw was found in the way HelixPlayer performed URLun-escaping. A specially-crafted URL string could cause HelixPlayer tocrash or, potentially, execute arbitrary code. (CVE-2010-0416)All HelixPlayer users are advised to upgrade to this updated package,which contains backported patches to resolve these issues. All runninginstances of HelixPlayer must be restarted for this update to take effect.

Solution(s)

  • redhat-upgrade-helixplayer

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;