RealNetworks Addresses Security Problems | eWeek

RealNetworks Addresses Security Problems

Verfasst von
Matt Hines
Matt Hines
Mar 24, 2006
2 minute read
eWeek Inhalte und Produktempfehlungen sind redaktionell unabhängig. Wir können Geld verdienen, wenn Sie auf Links zu unseren Partnern klicken. Mehr erfahren

RealNetworks has issued a security patch for a number of its products to address vulnerabilities that could allow for remote execution of code on devices running the software.

The company said that it has not been advised of any known exploitations of the flaws, which are present in its RealPlayer multimedia application Version 10.4 and 10.5 for Windows, and in both its RealPlayer 10.4 and Helix Player 1.4 for Linux.

Real recommended that customers using those products immediately upgrade to a current version of RealPlayer or Helix.

Among the four individual vulnerabilities detailed by the company, at least one could theoretically allow for execution of a program on computers running the affected products.

Another issue involves a malicious flash media (.swf) file, which the firm said could cause a buffer overrun on a customers machine.

/zimages/3/28571.gifClick hereto read about a recent RealPlayer vulnerability.

A third problem pertains to the potential for attacking the programs using a specially crafted Web page which could lead to a heap overflow in the applications embedded multimedia player.

The fourth issue disclosed by Real involves use of a malicious mimio file to cause a buffer overrun on an exploited machine.

Security researchers at iDefense, among the first to detail the issue publicly, issued an advisory to address the heap overflow problem specifically. Using the vulnerability, attackers could execute arbitrary code in the context of the individual currently logged onto the device.

The security company reported that the problem specifically exists in Reals handling of the “chunked” Transfer-Encoding method, which breaks the file a server is sending into pieces.

iDefense said there are multiple ways of triggering the vulnerability, each of which result in a heap overflow.

The company also offered a workaround for users of Reals affected products, which involves the disablement of certain Active X controls in the software.

iDefense said that to successfully exploit an end users device, an attacker would need to first lure the individual into clicking on a link to a server under the outsiders control. As a result, the company advised Real users to be on the lookout for malicious links and not to visit unknown Web sites.

Advertisement

Real dealt with a slew of serious security vulnerabilities in its programs at the end of 2005, releasing multiple updates to help its customers protect themselves against outside attacks.

/zimages/3/28571.gifCheck out eWEEK.coms for the latest security news, reviews and analysis. And for insights on security coverage around the Web, take a look at eWEEK.com Security Center Editor Larry Seltzers Weblog.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Eigentum von TechnologyAdvice. © 2026 TechnologyAdvice. Alle Rechte vorbehalten

Werbetreibenden-Offenlegung: Einige der auf dieser Website erscheinenden Produkte stammen von Unternehmen, von denen TechnologyAdvice eine Vergütung erhält. Diese Vergütung kann beeinflussen, wie und wo Produkte auf dieser Website erscheinen, einschließlich beispielsweise der Reihenfolge, in der sie erscheinen. TechnologyAdvice schließt nicht alle Unternehmen oder alle auf dem Marktplatz verfügbaren Produkttypen ein.