Welcome | Log In
Security

RealNetworks Patches 'Highly Critical' Flaw in Media Player

Print Version
E-Mail Article
Reprints

RealNetworks said on its Web site that it had not heard of any problems relating to this flaw. The vulnerability exists in almost all the versions of RealPlayer and RealOne for Windows, Mac operating systems and Linux, including Helix Player.


Verio MPS Solutions
Verio managed server solutions deliver the power and flexibility of a dedicated server at a fraction of the price. Learn more about how Verio gives you increased control, scalability, uptime, and performance.

RealNetworks (Nasdaq: RNWK) More about RealNetworks released a patch earlier this week for a "highly critical" security flaw discovered by Piotr Bania during a security audit of Real Player and reported to security firm Secunia More about Secunia.

Bania told TechNewsWorld that leaving the hole unpatched could lead to serious problems.

No Known Exploits

"At the time of this writing I have not come across an exploit in the wild, however, it is too early to say that an exploit will not be published in the near future," he said. "The risk is high and based on my experience I can see hackers exploiting this to their advantage. Whether it will be single incidents or a mass pandemic will be apparent in the coming days or weeks."

Attempts to reach RealNetworks were unsuccessful, but the company said on its Web site that it had not heard of any problems relating to this flaw.

The vulnerability exists in almost all the versions of RealPlayer and RealOne for Windows, Mac Consolidate Mac Servers. Run Windows Server on your Mac. Watch a Demo or Download a Trial. operating systems and Linux, including Helix Player.

The patch can be downloaded from the RealNetworks site , or by going to the tools menu, clicking "check for updates," selecting "Security Update - April 2005" and installing.

Hacker Code

If exploited, the buffer overflow fault could allow hackers to run their own code on RealPlayer users' computers. Bani said the problem is not uncommon.

"Current news from the bug-traq lists and other security portals indicate that vulnerabilities occur often and not only in RealNetworks products. As an example we can examine the number of vulnerabilities published in Microsoft's (Nasdaq: MSFT) More about Microsoft April Security Bulletins. Based on my experience I cannot rule out that similiar vulnerabilties will not occur in the future," he said.

Buffer overflow faults have also been found and fixed in the Mozilla More about Mozilla Foundation Foxfire browser, Windows Media Player, Mac's iSync and other popular software.

Social Networking Toolbox:

Print Version E-Mail Article Reprints More by Susan B. Shor   RSS

Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
  WiFi Hotspot Locator
City or Zip/Postal Code:
Country/Region:
ECT News Network Information
Locate Products and Services
Corporate
Reader Services
ECT News Network