RE: CR: ASM security vulnerability in rarender.dll

"Eric Hyche" <[email protected]> Thu, 17 Sep 2009 16:07:41 -0400
Newsgroups gmane.comp.multimedia.helix.devel
Organization RealNetworks, Inc.
Message-ID <008601ca37d2$83f4d180$8bde7480$@com>
Fix looks good. Please also check into hxclient_3_1_0_atlas and hxclient_4_0_1_brizo branches.

Eric

=======================================
Eric Hyche ([email protected])
Principal Engineer
RealNetworks, Inc.


>-----Original Message-----
>From: [email protected] [mailto:[email protected]]
>On Behalf Of Tad Yeager
>Sent: Thursday, September 17, 2009 3:52 PM
>To: [email protected]; [email protected]
>Subject: [Helix-client-dev] CR: ASM security vulnerability in rarender.dll
>
>Reported by an outside group, this bug can be triggered by playing back content with invalid ASM rule
>numbers in the packets.
>
>Per Rishi Matthew's comments on Steve Blanding's fix for a different ASM rulebook exploit, will
>checkin to HEAD, 347_atlas, 348_atlas, 349_atlas, 210_cays, 150_cay.
>
>Please let me know if this looks OK for checkin.
>Thanks,
>Tad Yeager
>