- Issued:
- 2010-12-14
- Updated:
- 2010-12-14
RHSA-2010:0981 - Security Advisory
Synopsis
Critical: HelixPlayer removal
Type/Severity
Security Advisory: Critical
Red Hat Insights patch analysis
Identify and remediate systems affected by this advisory.
Topic
Helix Player contains multiple security flaws and should no longer be used.
This update removes the HelixPlayer package from Red Hat Enterprise Linux
4.
The Red Hat Security Response Team has rated this update as having critical
security impact. Common Vulnerability Scoring System (CVSS) base scores,
which give detailed severity ratings, are available for each vulnerability
from the CVE links in the References section.
Description
Helix Player is a media player.
Multiple security flaws were discovered in RealPlayer. Helix Player and
RealPlayer share a common source code base; therefore, some of the flaws
discovered in RealPlayer may also affect Helix Player. Some of these flaws
could, when opening, viewing, or playing a malicious media file or stream,
lead to arbitrary code execution with the privileges of the user running
Helix Player. (CVE-2010-2997, CVE-2010-4375, CVE-2010-4378, CVE-2010-4379,
CVE-2010-4382, CVE-2010-4383, CVE-2010-4384, CVE-2010-4385, CVE-2010-4386,
CVE-2010-4392)
The Red Hat Security Response Team is unable to properly determine the
impact or fix all of these issues in Helix Player, due to the source code
for RealPlayer being unavailable.
Due to the security concerns this update removes the HelixPlayer package
from Red Hat Enterprise Linux 4. Users wishing to continue to use Helix
Player should download it directly from https://player.helixcommunity.org/
Solution
Before applying this update, make sure all previously-released errata
relevant to your system have been applied.
This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
http://kbase.redhat.com/faq/docs/DOC-11259
Affected Products
- Red Hat Enterprise Linux Server 4 x86_64
- Red Hat Enterprise Linux Server 4 i386
- Red Hat Enterprise Linux for x86_64 - Extended Update Support 4.8 x86_64
- Red Hat Enterprise Linux for x86_64 - Extended Update Support 4.8 i386
- Red Hat Enterprise Linux Workstation 4 x86_64
- Red Hat Enterprise Linux Workstation 4 i386
- Red Hat Enterprise Linux Desktop 4 x86_64
- Red Hat Enterprise Linux Desktop 4 i386
- Red Hat Enterprise Linux for Power, big endian 4 ppc
- Red Hat Enterprise Linux for Power, big endian - Extended Update Support 4.8 ppc
Fixes
- BZ - 662772 - CVE-2010-4384 HelixPlayer multiple flaws (CVE-2010-2997, CVE-2010-4375, CVE-2010-4378, CVE-2010-4379, CVE-2010-4382, CVE-2010-4383, CVE-2010-4385, CVE-2010-4386, CVE-2010-4392)
CVEs
Red Hat Enterprise Linux Server 4
SRPM | |
---|---|
HelixPlayer-1.0.6-3.el4_8.1.src.rpm | SHA-256: 270615498e41e4eb0db166da796e6f13389b06be231c7232ab951e7a57a70c53 |
x86_64 | |
HelixPlayer-uninstall-1.0.6-3.el4_8.1.i386.rpm | SHA-256: aec1f0259e032208e3dfdfc9db2c8c97bb3b8f5f7266a581c173a4ce1edb5d1c |
HelixPlayer-uninstall-1.0.6-3.el4_8.1.i386.rpm | SHA-256: aec1f0259e032208e3dfdfc9db2c8c97bb3b8f5f7266a581c173a4ce1edb5d1c |
i386 | |
HelixPlayer-uninstall-1.0.6-3.el4_8.1.i386.rpm | SHA-256: aec1f0259e032208e3dfdfc9db2c8c97bb3b8f5f7266a581c173a4ce1edb5d1c |
HelixPlayer-uninstall-1.0.6-3.el4_8.1.i386.rpm | SHA-256: aec1f0259e032208e3dfdfc9db2c8c97bb3b8f5f7266a581c173a4ce1edb5d1c |
Red Hat Enterprise Linux for x86_64 - Extended Update Support 4.8
SRPM | |
---|---|
HelixPlayer-1.0.6-3.el4_8.1.src.rpm | SHA-256: 270615498e41e4eb0db166da796e6f13389b06be231c7232ab951e7a57a70c53 |
x86_64 | |
HelixPlayer-uninstall-1.0.6-3.el4_8.1.i386.rpm | SHA-256: aec1f0259e032208e3dfdfc9db2c8c97bb3b8f5f7266a581c173a4ce1edb5d1c |
HelixPlayer-uninstall-1.0.6-3.el4_8.1.i386.rpm | SHA-256: aec1f0259e032208e3dfdfc9db2c8c97bb3b8f5f7266a581c173a4ce1edb5d1c |
i386 | |
HelixPlayer-uninstall-1.0.6-3.el4_8.1.i386.rpm | SHA-256: aec1f0259e032208e3dfdfc9db2c8c97bb3b8f5f7266a581c173a4ce1edb5d1c |
HelixPlayer-uninstall-1.0.6-3.el4_8.1.i386.rpm | SHA-256: aec1f0259e032208e3dfdfc9db2c8c97bb3b8f5f7266a581c173a4ce1edb5d1c |
Red Hat Enterprise Linux Workstation 4
SRPM | |
---|---|
HelixPlayer-1.0.6-3.el4_8.1.src.rpm | SHA-256: 270615498e41e4eb0db166da796e6f13389b06be231c7232ab951e7a57a70c53 |
x86_64 | |
HelixPlayer-uninstall-1.0.6-3.el4_8.1.i386.rpm | SHA-256: aec1f0259e032208e3dfdfc9db2c8c97bb3b8f5f7266a581c173a4ce1edb5d1c |
i386 | |
HelixPlayer-uninstall-1.0.6-3.el4_8.1.i386.rpm | SHA-256: aec1f0259e032208e3dfdfc9db2c8c97bb3b8f5f7266a581c173a4ce1edb5d1c |
Red Hat Enterprise Linux Desktop 4
SRPM | |
---|---|
HelixPlayer-1.0.6-3.el4_8.1.src.rpm | SHA-256: 270615498e41e4eb0db166da796e6f13389b06be231c7232ab951e7a57a70c53 |
x86_64 | |
HelixPlayer-uninstall-1.0.6-3.el4_8.1.i386.rpm | SHA-256: aec1f0259e032208e3dfdfc9db2c8c97bb3b8f5f7266a581c173a4ce1edb5d1c |
i386 | |
HelixPlayer-uninstall-1.0.6-3.el4_8.1.i386.rpm | SHA-256: aec1f0259e032208e3dfdfc9db2c8c97bb3b8f5f7266a581c173a4ce1edb5d1c |
Red Hat Enterprise Linux for Power, big endian 4
SRPM | |
---|---|
HelixPlayer-1.0.6-3.el4_8.1.src.rpm | SHA-256: 270615498e41e4eb0db166da796e6f13389b06be231c7232ab951e7a57a70c53 |
ppc | |
HelixPlayer-uninstall-1.0.6-3.el4_8.1.ppc.rpm | SHA-256: 9fc563964294e56b98867391961fcda10a7628be8c591d0d82bdb2559454807f |
Red Hat Enterprise Linux for Power, big endian - Extended Update Support 4.8
SRPM | |
---|---|
HelixPlayer-1.0.6-3.el4_8.1.src.rpm | SHA-256: 270615498e41e4eb0db166da796e6f13389b06be231c7232ab951e7a57a70c53 |
ppc | |
HelixPlayer-uninstall-1.0.6-3.el4_8.1.ppc.rpm | SHA-256: 9fc563964294e56b98867391961fcda10a7628be8c591d0d82bdb2559454807f |
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.