Welcome to P2PNET.net - The original daily p2p and digital news site. Always First!
Register | Login
RIAA News
Cool Stuff
MPAA News
Games / Consoles
News
Music
Movies
TV
Open Source
Mobiles
Advertising
Product News
P2P
Off Topic
Freedom
Politics
Interviews
Security
DRM
Links
p2pnet Digests
Search: 
Search
 
Web P2PNET   
Search: 
Search
Torrent Site Tracker
MP3Rocket
 
Add real-time p2pnet headlines to YOUR site ! Click here to download our newsfeed code
p2pnet - rss feed: http://p2pnet.net/p2p.rss | p2pnet celebrities: http://p2pnet.net/celeb.rss | Mobile? http://p2pnet.net/index-wml.php

RealPlayer security holes

RealNetworks says some of its players have ‘Security Vulnerabilities’ that could “potentially allow an attacker to run arbitrary code on a user’s machine”.

Put another way, if you’re running a suspect version, someone could hack your PC and take control unless you implement the appropropriate fix, which you’ll find here.

Affected are:

RealOne Player, RealOne Player v2 for Windows only (all languages), RealPlayer 10 Beta (English only) and RealOne Enterprise Desktop or RealPlayer Enterprise (all versions, standalone and as configured by the RealOne Desktop Manager or RealPlayer Enterprise Manager) - Exploit 1.

RealOne Player, RealOne Player v2 (all language versions, all platforms), and RealOne Enterprise Desktop or RealPlayer Enterprise (all versions, standalone and as configured by the RealOne Desktop Manager or RealPlayer Enterprise Manager) - Exploit 2.

RealOne Player and RealPlayer 8 (all language versions) - Exploit 3.

Exploit 1 allows exploiters to “operate remote Javascript from the domain of the URL opened by a SMIL file or other file”.

Exploit 2 allows exploiters to “fashion RMP files which allow an attacker to download and execute arbitrary code on a user’s machine”.

Exploit 3 allows exploiters to “fashion media files to create ‘Buffer Overrun’ errors”.

“While we have not received reports of anyone actually being attacked with this exploit, all security vulnerabilities are taken very seriously by RealNetworks,” says the company.

HOME

One Response to “RealPlayer security holes”

  1. Reader's Write Says:

    Ohboy I’m not surprised. I’ve NEVER liked realplayer, not from day one and there were things said about it back then that made me not trust it and it’s never been on my machine.

    Just yesterday I tried to view a video and it required RealPlayer and as much as I wanted to see it, there was no way in hell I’d get that player and now I read this. I’m glad I follow my instincts and glad you’ve warned people about the security hole.

    Now I can laugh. hahaha.

Leave a Reply

    Advertisments
TekSavvy