Highly critical RealNetworks flaws
p2pnet.net News:- More "highly critical" security holes have been found in RealNetworks media players.
In February and June this year, RealNetworks said players had ‘Security Vulnerabilities’ that could "potentially" allow hackers to run code on a user’s machines.
On September 28, it issued the basically same message with the same bland statement, "all security vulnerabilities are taken very seriously by RealNetworks".
Denmark’s Secunia says the "highly critical" multiple vulnerabilities can be maliciously exploited by hackers to compromise a user’s system and delete files.
Affected are:
- Helix Player 1.x
- RealOne Player v1
- RealOne Player v2
- RealPlayer 10
- RealPlayer 8
- RealPlayer Enterprise
RealNetworks hadn’t posted a warning on its RealPlayer consumer site when we checked it at around 7:45 am Pacific.
You can get the latest fixes from the support page.
==================
See:-
run code - Security flaws fixed: Real, p2pnet, June 11, 2004
bland statement - RealNetworks, Inc. Releases Update to Address Security Vulnerabilities, RealNetworks, September 28, 2004
highly critical - RealOne Player / RealPlayer / Helix Player Multiple Vulnerabilities, Secunia, September 29, 2004





p2pnet - rss feed: 
October 1st, 2004 at 4:36 pm
real has always been full of holes