Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
200

Scientific Linux: 2010-12-14 Critical HelixPlayer Code Execution Risk

Critical: HelixPlayer removal. Date: Fri, 17 Dec 2010 11:29:17 -0600 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA Critical: HelixPlayer on SL4.x i386/x86_64 Comments: To: "This email address is being protected from spambots. You need JavaScript enabled to view it." Synopsis: Critical: HelixPlayer removal Issue date: 2010-12-14 CVE Names: CVE-2010-2997 CVE-2010-4375 CVE-2010-4378 CVE-2010-4379 CVE-2010-4382 CVE-2010-4383 CVE-2010-4384 CVE-2010-4385 CVE-2010-4386 CVE-2010-4392 Multiple security flaws were discovered in RealPlayer. Helix Player and RealPlayer share a common source code base; therefore, some of the flaws discovered in RealPlayer may also affect Helix Player. Some of these flaws could, when opening, viewing, or playing a malicious media file or stream, lead to arbitrary code execution with the privileges of the user running Helix Player. (CVE-2010-2997, CVE-2010-4375, CVE-2010-4378, CVE-2010-4379, CVE-2010-4382, CVE-2010-4383, CVE-2010-4384, CVE-2010-4385, CVE-2010-4386, CVE-2010-4392) Our removal packages have nothing in them but a README, so the HelixPlayer program will be removed from your SL 4 machine, but you will still have a package called HelixPlayer. Note: Just to be clear. You will still have a package called HelixPlayer on your machine, but there will not be any program in it. It will be an empty rpm. SL 4.x SRPMS: HelixPlayer-1.0.6-3.sl4.1.src.rpm i386: HelixPlayer-1.0.6-3.sl4.1.i386.rpm HelixPlayer-uninstall-1.0.6-3.sl4.1.i386.rpm x86_64: HelixPlayer-1.0.6-3.sl4.1.i386.rpm HelixPlayer-uninstall-1.0.6-3.sl4.1.i386.rpm -Connie Sieh -Troy Dawson . DataAnalyzer has been discontinued due to various vulnerabilities posing risks of unauthorized access.. HelixPlayer, Critical Security Advisory, Scientific Linux, Code Execution Risks. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Dec 17, 2010 Critical Scientific Linux
91

Gentoo: 200504-21 Normal Severity: RealPlayer Buffer Overflow

RealPlayer and Helix Player are vulnerable to a buffer overflow that could lead to remote execution of arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200504-21 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: RealPlayer, Helix Player: Buffer overflow vulnerability Date: April 22, 2005 Bugs: #89862 ID: 200504-21 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= RealPlayer and Helix Player are vulnerable to a buffer overflow that could lead to remote execution of arbitrary code. Background ========= RealPlayer is a multimedia player capable of handling multiple multimedia file formats. Helix Player is the Open Source version of RealPlayer. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 media-video/realplayer < 10.0.4 > = 10.0.4 2 media-video/helixplayer < 1.0.4 > = 1.0.4 ------------------------------------------------------------------- 2 affected packages on all of their supported architectures. ------------------------------------------------------------------- Description ========== Piotr Bania has discovered a buffer overflow vulnerability in RealPlayer and Helix Player when processing malicious RAM files. Impact ===== By enticing a user to play a specially crafted RAM file an attacker could execute arbitrary code with the permissions of the user running the application. Workaround ========= There is no known workaround at this time. Resolution ========= All RealPlayer usersshould upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =media-video/realplayer-10.0.4" All Helix Player users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =media-video/helixplayer-1.0.4" References ========= [ 1 ] CAN-2005-0755 https://www.cve.org/CVERecord?id=CAN-2005-0755 [ 2 ] RealNetworks Advisory https://www.real.com/ Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200504-21 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. License ====== Copyright 2005 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.0/ . Both RealPlayer and Helix Player on Gentoo systems are vulnerable to a critical buffer overflow flaw, which may allow for remote code execution. Ensure you update your software immediately!. RealPlayer, Helix Player, Buffer Overflow, Remote Execution, Gentoo Security. . LinuxSecurity.com Team

Calendar 2 Apr 22, 2005 Gentoo
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here