Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Patch Released for 'Highly Critical' RealPlayer Flaw
GeekCoffee ^ | April 22, 2005 | GeekCoffee

Posted on 04/22/2005 10:12:30 AM PDT by holymoly

RealNetworks has released a security patch to fix a flaw in its RealPlayer software that could allow compromised code to be run on users computers. The flaw, which was rated "highly critical" by Secunia, is in the most recent versions of the software for both Windows and OS X. Also, Secunia said that some of the older Linux versions were at risk for the flaw.

"RealNetworks has received no reports of machines compromised as a result of the now-remedied vulnerabilities," the company said on its website. "RealNetworks takes all security vulnerabilities very seriously."


TOPICS: Computers/Internet
KEYWORDS: bug; flaw; patch; player; real; realnetworks; realplayer; security; spyware
For those interested in an alternative to RealPlayer: CleanSoftware.org lists Real Alternative

Freeware : Windows
Checked: version 1.29

Real Alternative will allow you to play RealMedia files without having to install RealPlayer or RealOne Player from Real Networks. Supports content embedded in web pages, RealAudio (.ra .rpm), RealMedia (.rm .ram .rmvb .rpx .smi .smil), RealText (.rt), and ReadPix (.rp). Comes packaged with Media Player Classic (MPC) and codecs.


I haven't tested it, but it may be a viable alternative to Real Player (which many people consider spyware).
1 posted on 04/22/2005 10:12:38 AM PDT by holymoly
[ Post Reply | Private Reply | View Replies]

To: WestCoastGal

pong


2 posted on 04/22/2005 10:16:29 AM PDT by ChefKeith (Apply here to be added to the NASCAR Ping List, Daytona is done but we got 29 more races to go...)
[ Post Reply | Private Reply | To 1 | View Replies]

To: holymoly

More Information:




Viral movies possible with RealPlayer flaw
Published: October 1, 2004, 4:25 PM PDT
By Robert Lemos
Staff Writer, CNET News.com
TrackBackPrintE-mailTalkBack
A software slipup in RealNetworks' music player means that Windows, Mac and Linux computers could be compromised by a fake movie file, a security company said Friday.

The problem means that fake movie files could be created that, when played by vulnerable Real software, would run a program instead. The flaw appears in RealPlayer 10 for Windows and Mac OS X, the RealOne Player for Windows and Mac OS X and the Real Helix Player for Linux.

"Anyone who has RealPlayer is affected, and there are many people with RealPlayer," said Marc Maiffret, chief hacking officer at software security company eEye Digital Security, the company that discovered the security issue.

RealNetworks could not immediately be reached for comment.

RealNetworks has issued patches for the flaw.

The flaw occurs in a component of Real's software that handles Real movie files with the .rm extension, according to eEye's advisory.

Similar to the recent flaw in Windows applications that handle the JPEG image format, this vulnerability affects a widespread piece of software and could be used to create a virus.

"It's similar to the JPEG flaw in the sense that just by viewing the file, or having the file 'force viewed' through a Web browser, your system can be compromised," Maiffret said. "I think both this JPEG vulnerability and the RealPlayer vulnerability are good examples of a type of threat that is becoming more prevalent: client-side vulnerabilities."

Rather than finding a security hole in the operating system and gaining direct access to a computer, attackers are now increasingly looking at exploiting widely used applications.

"Most security software...is not able to defend itself well against these client-based vulnerabilities, leaving companies with few alternatives other than patching," Maiffret said.


3 posted on 04/22/2005 10:43:12 AM PDT by Swordmaker (tagline now open, please ring bell.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Bush2000; antiRepublicrat; Action-America; eno_; N3WBI3; zeugma; TechJunkYard; ShorelineMike; ...
Mac Realplayer users security PING!

Update your Realplayer software NOW!

Or get rid of it...

If you want on or off the Mac Ping List, Freepmail me.

4 posted on 04/22/2005 10:44:49 AM PDT by Swordmaker (tagline now open, please ring bell.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker

Woah!

Thanks!


5 posted on 04/22/2005 10:48:53 AM PDT by tiamat (Some days, it's not even worth chewing through the restraints.)
[ Post Reply | Private Reply | To 4 | View Replies]

To: Swordmaker

"The flaw appears in RealPlayer 10 for Windows and Mac OS X, the RealOne Player for Windows and Mac OS X and the Real Helix Player for Linux."

But the upgrade is *free*. ;')


6 posted on 04/22/2005 11:03:58 AM PDT by SunkenCiv (FR profiled updated Monday, April 11, 2005. Fewer graphics, faster loading.)
[ Post Reply | Private Reply | To 3 | View Replies]

To: holymoly
Here's the Ultimate patch for Real Player.
7 posted on 04/22/2005 11:15:49 AM PDT by Bloody Sam Roberts (The way that you wander is the way that you choose. The day that you tarry is the day that you lose.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Bloody Sam Roberts
Agreed re MPC.

Real(anything) is real shite.
period.

8 posted on 04/22/2005 4:11:59 PM PDT by tomkat
[ Post Reply | Private Reply | To 7 | View Replies]

To: Swordmaker

bttt


9 posted on 04/23/2005 3:45:35 AM PDT by lainde
[ Post Reply | Private Reply | To 4 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson