Bug 106048 (CVE-2005-2629) - VUL-0: CVE-2005-2629: buffer overflow in realplayer before 1.0.6
Summary: VUL-0: CVE-2005-2629: buffer overflow in realplayer before 1.0.6
Status: RESOLVED FIXED
: 119017 (view as bug list)
Alias: CVE-2005-2629
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: All All
: P5 - None : Critical
Target Milestone: ---
Assignee: Stanislav Brabec
QA Contact: Security Team bot
URL:
Whiteboard: CVE-2005-2629: CVSS v2 Base Score: 5....
Keywords:
Depends on:
Blocks:
 
Reported: 2005-08-21 15:28 UTC by Marcus Meissner
Modified: 2021-11-04 16:31 UTC (History)
6 users (show)

See Also:
Found By: Third Party Developer/Partner
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 1 Marcus Meissner 2005-08-21 15:28:51 UTC
note: disclosure 30.8.2005. 
Comment 2 Petr Mladek 2005-08-22 13:34:41 UTC
Standa has vacation the following two weeks. I can prepare the update. I would
need some help because I do not know the details about our RealPlayer-related
contracts.

Do we have access to the fixed binaries already now? Or do I have to wait until
30 August when the fixed binaries are officialy available?

Do we need to run the quick test plan on our platform? Who will run it (me, QA,
anybody else)?

Thanks for help,
Petr
Comment 3 Marcus Meissner 2005-08-22 13:38:40 UTC
I just have this mail, nothing more for now. 
 
The mail seems to suggest we get them on August 30th. 
 
I also am not familar where the packages are, Stanislav did that. 
 
The testplan is run by one of our india colleagues. 
Comment 6 Marcus Meissner 2005-09-01 07:07:50 UTC
CRD 15.9.2005 
Comment 10 Marcus Meissner 2005-09-05 09:24:59 UTC
SWAMPID: 2211 
Comment 11 Marcus Meissner 2005-09-05 09:30:06 UTC
patchinfos submitted. 
Comment 13 Petr Mladek 2005-09-07 09:59:06 UTC
Are the binaries for ppc available somewhere? Thanks for help.
Comment 14 Thomas Biege 2005-09-08 10:47:41 UTC
approved binary packages we had so far.
Comment 15 Andreas Jaeger 2005-09-09 05:00:30 UTC
I don't have informatoin about ppc binares.
Comment 17 Ludwig Nussel 2005-09-09 12:31:28 UTC
*sigh* are we even allowed to release the previous update? Please prepare new 
packages in any case. 
Comment 18 Stanislav Brabec 2005-09-09 13:33:57 UTC
I will ask for new builds.
Comment 19 Marcus Meissner 2005-09-11 20:09:43 UTC
Note that the *bleep* date *changed* three times. 
 
Even silently from 15th to 19th of September. 
Comment 20 Stanislav Brabec 2005-09-12 08:26:43 UTC
From: 	Donya Shirzad <dshirzad@real.com>
To: 	Stanislav Brabec <sbrabec@suse.cz>, Donya Shirzad <dshirzad@real.com>
Cc: 	novell-private-dev <novell-private-dev@helixcommunity.org>
Subject: 	Re: [Novell-private-dev] Another (optional) Security Update of RealPlayer
Date: 	Fri, 09 Sep 2005 11:09:43 -0700  (20:09 CEST)

At 03:36 PM 9/9/2005 +0200, Stanislav Brabec wrote:
>Hallo. We decided to do this update. Could you provide URL, where I can
>download new builds?

We'll be putting the updated build in the novell-private project at the end 
of next week.  I'll send out another email with the required URLs.

Thanks,
- Donya
Comment 22 Stanislav Brabec 2005-09-16 11:42:44 UTC
For 10.0, I will add fix for bug 117078 altogether with this security update.
Comment 24 Marcus Meissner 2005-09-17 20:41:31 UTC
current CRD: 18.10.2005 
Comment 25 Stanislav Brabec 2005-09-20 13:14:09 UTC
Packages submitted for:
9.2-i386, 9.3-i386, sles9-sld-i386: Fix for this bug only.
10.0-i386, STABLE-i386: With aoss preloader. Please follow bug 117078 for test plan.

I don't have PPC builds yet.
Comment 26 Marcus Meissner 2005-09-27 13:46:37 UTC
we will wait with checkin until the day of disclosure nears. 
 
 
there was also a mail on full-disclosure probably reporting some of the 
problems here already to the public. 
Comment 28 Marcus Meissner 2005-09-28 04:58:55 UTC
*** Bug 119017 has been marked as a duplicate of this bug. ***
Comment 29 Marcus Meissner 2005-09-28 05:20:26 UTC
stanislav, we need the indian test guy to run the testsuite ... 
do you still have his name / address? 
Comment 31 Stanislav Brabec 2005-09-29 09:20:18 UTC
There are addresses from test report from April:
Thanikachalam S <sthanikachalam@novell.com>
Rajasekhar Inguva <RInguva@novell.com>

Please note them about special need to test 10.0 with aoss (please follow bug
117078 for more).

And please don't close the bug until PPC gets fixed.
Comment 32 Marcus Meissner 2005-09-30 08:43:32 UTC
I just sent off a query mail to the indian testengineers. 
Comment 33 Michael Schröder 2005-10-04 16:28:32 UTC
Where's the 10.0-ppc version? 
Comment 34 Stanislav Brabec 2005-10-04 16:50:12 UTC
I have just asked for PPC binaries again.
Comment 35 Marcus Meissner 2005-10-05 06:04:30 UTC
We are not shipping RealPlayer PPC binaries, so this must not block the 
checkin. 
 
Please checkin the i386 packages ASAP. 
Comment 37 Marcus Meissner 2005-10-10 13:20:24 UTC
we released the CAN-2005-2710 part and announce it.  
  
The CAN-2005-2629 part (buffer overflow) is NOT PUBLIC yet. (perhaps oct 18, 
unclear) 
Comment 38 Marcus Meissner 2005-10-14 14:04:50 UTC
stanislav ...  do you know if we released the bugfix for the other problem 
in here with the last update too? 
 
or if we need to do a full update again? 
Comment 39 Stanislav Brabec 2005-10-14 14:13:23 UTC
I have only replaced old tarball of 10.0.6 with newer one. I guess that no fix
was removed from newer tarball.
Comment 40 Ludwig Nussel 2005-11-11 08:27:22 UTC
CVE-2005-2629 is public now
Comment 41 Marcus Meissner 2005-11-11 09:45:46 UTC
ok, i guess we can close it. we released it earlier, unannounced.

i will put a note into our summary advisory this week.
Comment 42 Stanislav Brabec 2005-12-08 16:21:41 UTC
Fixed package submitted to STABLE.
Comment 43 Thomas Biege 2009-10-13 20:45:49 UTC
CVE-2005-2629: CVSS v2 Base Score: 5.1 (AV:N/AC:H/Au:N/C:P/I:P/A:P)