Debian Bug report logs -
#132528
realplayer: Buffer Overrun Exploit
Reported by: Nicolas Lidzborski <cpc@freeshell.org>
Date: Wed, 6 Feb 2002 00:18:05 UTC
Severity: grave
Tags: security
Found in version 8.0.6
Done: Colin Watson <cjwatson@debian.org>
Bug is archived. No further changes may be made.
Toggle useless messages
Report forwarded to debian-bugs-dist@lists.debian.org, Brian Russo <wolfie@debian.org>, realplayer@packages.qa.debian.org:
Bug#132528; Package realplayer.
(full text, mbox, link).
Acknowledgement sent to Nicolas Lidzborski <cpc@freeshell.org>:
New Bug report received and forwarded. Copy sent to Brian Russo <wolfie@debian.org>, realplayer@packages.qa.debian.org.
(full text, mbox, link).
Message #5 received at submit@bugs.debian.org (full text, mbox, reply):
Package: realplayer
Version: 8.0.6
Severity: grave
Tags: security
Justification: user security hole
Real has discovered a buffer overrun in one of their libs used by RealPlayer.
They provide a new lib to replace the flawed one.
Check:
http://www.service.real.com/help/faq/security/bufferoverrun.html
Could be a good idea to download the patch (just the rmffplin library) and
to strip it afterwards.
-- System Information
Debian Release: 3.0
Architecture: i386
Kernel: Linux gandalf.intalio.com 2.4.14 #6 Sat Nov 10 13:25:00 PST 2001 i686
Locale: LANG=C, LC_CTYPE=fr_FR@euro
Versions of packages realplayer depends on:
ii cpio 2.4.2-39 GNU cpio -- a program to manage ar
ii debconf 1.0.25 Debian configuration management sy
ii libc6 2.2.4-7 GNU C Library: Shared libraries an
ii xlib6g 4.1.0-13 pseudopackage providing X librarie
ii xlibs 4.1.0-13 X Window System client libraries
Information forwarded to debian-bugs-dist@lists.debian.org, Brian Russo <wolfie@debian.org>, realplayer@packages.qa.debian.org:
Bug#132528; Package realplayer.
(full text, mbox, link).
Acknowledgement sent to Brian Russo <brian@entropy.net>:
Extra info received and forwarded to list. Copy sent to Brian Russo <wolfie@debian.org>, realplayer@packages.qa.debian.org.
(full text, mbox, link).
Message #10 received at 132528@bugs.debian.org (full text, mbox, reply):
Is this .so freely distributable?
probably not, I don't see how I would really go about
'patching' this if I cannot distribute the patch.
Real has not released a new version of the RPM (still cs2),
so unless they have 'silently' added the new .so,
there's not much I can do. Else I could release a new .deb,
which asks for the new rpm. Better than nothing, 'twould be.
Perhaps I should make some kind of announcement telling people to
apply the patch themselves.
I'm open to suggestions...
- bri
At Tue, Feb 05, 2002 at 04:12:17PM -0800, Nicolas Lidzborski wrote:
> Package: realplayer
> Version: 8.0.6
> Severity: grave
> Tags: security
> Justification: user security hole
>
> Real has discovered a buffer overrun in one of their libs used by RealPlayer.
> They provide a new lib to replace the flawed one.
>
> Check:
> http://www.service.real.com/help/faq/security/bufferoverrun.html
>
> Could be a good idea to download the patch (just the rmffplin library) and
> to strip it afterwards.
--
/\_/\ Brian Russo <brian@entropy.net>
\. ./ Debian/GNU Linux Developer <wolfie@debian.org>
/\_/\ 404E 87E8 DD0C 275B 742B 09AD 2243 839C 54D8 1666
Information forwarded to debian-bugs-dist@lists.debian.org, Brian Russo <wolfie@debian.org>, realplayer@packages.qa.debian.org:
Bug#132528; Package realplayer.
(full text, mbox, link).
Acknowledgement sent to Jamie Wilkinson <jaq@spacepants.org>:
Extra info received and forwarded to list. Copy sent to Brian Russo <wolfie@debian.org>, realplayer@packages.qa.debian.org.
(full text, mbox, link).
Message #15 received at 132528@bugs.debian.org (full text, mbox, reply):
This one time, at band camp, Brian Russo wrote:
>Is this .so freely distributable?
>probably not, I don't see how I would really go about
>'patching' this if I cannot distribute the patch.
>
>Real has not released a new version of the RPM (still cs2),
>so unless they have 'silently' added the new .so,
>there's not much I can do. Else I could release a new .deb,
>which asks for the new rpm. Better than nothing, 'twould be.
You could download the extra .so in your postinst and install it, or add a
debconf note suggesting that the admin downloads it to a place where you can
install it from.
--
jaq@spacepants.org http://spacepants.org/jaq.gpg
<dopey_rant> polls = trolls
Information forwarded to debian-bugs-dist@lists.debian.org, Brian Russo <wolfie@debian.org>, realplayer@packages.qa.debian.org:
Bug#132528; Package realplayer.
(full text, mbox, link).
Acknowledgement sent to Brian Russo <brian@entropy.net>:
Extra info received and forwarded to list. Copy sent to Brian Russo <wolfie@debian.org>, realplayer@packages.qa.debian.org.
(full text, mbox, link).
Message #20 received at 132528@bugs.debian.org (full text, mbox, reply):
At Wed, Feb 06, 2002 at 12:38:21PM +1100, Jamie Wilkinson wrote:
> This one time, at band camp, Brian Russo wrote:
> >Is this .so freely distributable?
> >probably not, I don't see how I would really go about
> >'patching' this if I cannot distribute the patch.
> >
> >Real has not released a new version of the RPM (still cs2),
> >so unless they have 'silently' added the new .so,
> >there's not much I can do. Else I could release a new .deb,
> >which asks for the new rpm. Better than nothing, 'twould be.
>
> You could download the extra .so in your postinst and install it, or add a
> debconf note suggesting that the admin downloads it to a place where you can
> install it from.
I don't like the downloading-from-the-web idea,
mainly because it's buggy and won't work for everyone.
I emailed -user with a mini advisory for now.
Information forwarded to debian-bugs-dist@lists.debian.org, Brian Russo <wolfie@debian.org>, realplayer@packages.qa.debian.org:
Bug#132528; Package realplayer.
(full text, mbox, link).
Acknowledgement sent to Matt Zimmerman <mdz@debian.org>:
Extra info received and forwarded to list. Copy sent to Brian Russo <wolfie@debian.org>, realplayer@packages.qa.debian.org.
(full text, mbox, link).
Message #25 received at 132528@bugs.debian.org (full text, mbox, reply):
realplayer has now been removed from woody because of this bug. Do you have
plans to do something about this?
--
- mdz
Information forwarded to debian-bugs-dist@lists.debian.org, Brian Russo <wolfie@debian.org>, realplayer@packages.qa.debian.org:
Bug#132528; Package realplayer.
(full text, mbox, link).
Acknowledgement sent to Martin Michlmayr <tbm@cyrius.com>:
Extra info received and forwarded to list. Copy sent to Brian Russo <wolfie@debian.org>, realplayer@packages.qa.debian.org.
(full text, mbox, link).
Message #30 received at 132528@bugs.debian.org (full text, mbox, reply):
* Matt Zimmerman <mdz@debian.org> [20020310 11:38]:
> realplayer has now been removed from woody because of this bug. Do
> you have plans to do something about this?
Matt, realplayer has been orphaned. Thomas Seyrat wanted to adopt it
but he's waiting for the DAM to approve him. Perhaps you want to
sponsor his upload?
--
Martin Michlmayr
tbm@cyrius.com
Information forwarded to debian-bugs-dist@lists.debian.org, Brian Russo <wolfie@debian.org>, realplayer@packages.qa.debian.org:
Bug#132528; Package realplayer.
(full text, mbox, link).
Acknowledgement sent to Thomas Seyrat <thomas@glou.net>:
Extra info received and forwarded to list. Copy sent to Brian Russo <wolfie@debian.org>, realplayer@packages.qa.debian.org.
(full text, mbox, link).
Message #35 received at 132528@bugs.debian.org (full text, mbox, reply):
Martin Michlmayr écrivait:
> * Matt Zimmerman <mdz@debian.org> [20020310 11:38]:
> > realplayer has now been removed from woody because of this bug. Do
> > you have plans to do something about this?
> Matt, realplayer has been orphaned. Thomas Seyrat wanted to adopt it
> but he's waiting for the DAM to approve him. Perhaps you want to
> sponsor his upload?
Indeed I recently adopted this package, and prepared a preliminary
new version fixing some of the minor bugs. Yet, as I am not yet a real
debconf expert, I have some trouble fixing the RC one, since the
security problem has to be fixed with user intervention at postinst
time.
I hope I can find how to fix it soon, then give it to a DD for upload.
--
Thomas Seyrat.
Information forwarded to debian-bugs-dist@lists.debian.org, Brian Russo <wolfie@debian.org>, realplayer@packages.qa.debian.org:
Bug#132528; Package realplayer.
(full text, mbox, link).
Acknowledgement sent to Matt Zimmerman <mdz@debian.org>:
Extra info received and forwarded to list. Copy sent to Brian Russo <wolfie@debian.org>, realplayer@packages.qa.debian.org.
(full text, mbox, link).
Message #40 received at 132528@bugs.debian.org (full text, mbox, reply):
On Sun, Mar 10, 2002 at 07:36:53PM +0100, Martin Michlmayr wrote:
> * Matt Zimmerman <mdz@debian.org> [20020310 11:38]:
> > realplayer has now been removed from woody because of this bug. Do
> > you have plans to do something about this?
>
> Matt, realplayer has been orphaned. Thomas Seyrat wanted to adopt it
> but he's waiting for the DAM to approve him. Perhaps you want to
> sponsor his upload?
I didn't realize this...the realplayer in unstable still says:
Maintainer: Brian Russo <wolfie@debian.org>
I will see about sponsoring an upload when Thomas has fixed packages.
--
- mdz
Reply sent to Colin Watson <cjwatson@debian.org>:
You have taken responsibility.
(full text, mbox, link).
Notification sent to Nicolas Lidzborski <cpc@freeshell.org>:
Bug acknowledged by developer.
(full text, mbox, link).
Message #45 received at 132528-done@bugs.debian.org (full text, mbox, reply):
Hi,
The realplayer package has been removed from the Debian archive, so I'm
closing its bugs. If anybody is going to reintroduce it, please be sure
to fix at least the release-critical bugs first.
=========================================================================
[Date: Mon, 11 Nov 2002 06:43:42 -0500] [ftpmaster: Anthony Towns]
Removed the following packages from unstable:
realplayer | 8.0.6 | source, i386
------------------- Reason -------------------
purged by RM; see bugs 132528 143626 150806
----------------------------------------------
=========================================================================
Regards,
--
Colin Watson [cjwatson@flatline.org.uk]
Send a report that this bug log contains spam.
Debian bug tracking system administrator <owner@bugs.debian.org>.
Last modified:
Mon Jun 5 02:11:16 2023;
Machine Name:
buxtehude
Debian Bug tracking system
Debbugs is free software and licensed under the terms of the GNU
Public License version 2. The current version can be obtained
from https://bugs.debian.org/debbugs-source/.
Copyright © 1999 Darren O. Benham,
1997,2003 nCipher Corporation Ltd,
1994-97 Ian Jackson,
2005-2017 Don Armstrong, and many other contributors.