Date:         Wed, 27 Jun 2007 14:43:58 -0500
Reply-To:     Troy Dawson 
Sender:       Security Errata for Scientific Linux
              
From:         Troy Dawson 
Subject:      Security ERRATA for HelixPlayer on SL4.x i386/x86_64
Comments: To: scientific-linux-errata@fnal.gov

Synopsis:	Critical: HelixPlayer security update
Issue date:	2007-06-27
CVE Names:	CVE-2007-3410

A buffer overflow flaw was found in the way HelixPlayer processed
Synchronized Multimedia Integration Language (SMIL) files. It was possible
for a malformed SMIL file to execute arbitrary code with the permissions of
the user running HelixPlayer. (CVE-2007-3410)

SL 4.x

   SRPMS:
	HelixPlayer-1.0.6-0.EL4.2.0.2.src.rpm
   i386:
	HelixPlayer-1.0.6-0.EL4.2.0.2.i386.rpm
   x86_64:
	HelixPlayer-1.0.6-0.EL4.2.0.2.i386.rpm

-Connie Sieh
-Troy Dawson

SciLinux: CVE-2007-3410 HelixPlayer SL4.x i386/x86_64

Critical: HelixPlayer security update

Summary

Date:         Wed, 27 Jun 2007 14:43:58 -0500Reply-To:     Troy Dawson Sender:       Security Errata for Scientific Linux              From:         Troy Dawson Subject:      Security ERRATA for HelixPlayer on SL4.x i386/x86_64Comments: To: scientific-linux-errata@fnal.govSynopsis:	Critical: HelixPlayer security updateIssue date:	2007-06-27CVE Names:	CVE-2007-3410A buffer overflow flaw was found in the way HelixPlayer processedSynchronized Multimedia Integration Language (SMIL) files. It was possiblefor a malformed SMIL file to execute arbitrary code with the permissions ofthe user running HelixPlayer. (CVE-2007-3410)SL 4.x   SRPMS:	HelixPlayer-1.0.6-0.EL4.2.0.2.src.rpm   i386:	HelixPlayer-1.0.6-0.EL4.2.0.2.i386.rpm   x86_64:	HelixPlayer-1.0.6-0.EL4.2.0.2.i386.rpm-Connie Sieh-Troy Dawson



Security Fixes

Severity

Related News