RealNetworks Addresses Security Problems

執筆者
Matt Hines
Matt Hines
Published: Mar 24, 2006
Updated: Feb 2, 2021
2 minute read
eWeek のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

RealNetworks has issued a security patch for a number of its products to address vulnerabilities that could allow for remote execution of code on devices running the software.

The company said that it has not been advised of any known exploitations of the flaws, which are present in its RealPlayer multimedia application Version 10.4 and 10.5 for Windows, and in both its RealPlayer 10.4 and Helix Player 1.4 for Linux.

Real recommended that customers using those products immediately upgrade to a current version of RealPlayer or Helix.

Among the four individual vulnerabilities detailed by the company, at least one could theoretically allow for execution of a program on computers running the affected products.

Another issue involves a malicious flash media (.swf) file, which the firm said could cause a buffer overrun on a customers machine.

/zimages/3/28571.gifClick hereto read about a recent RealPlayer vulnerability.

A third problem pertains to the potential for attacking the programs using a specially crafted Web page which could lead to a heap overflow in the applications embedded multimedia player.

The fourth issue disclosed by Real involves use of a malicious mimio file to cause a buffer overrun on an exploited machine.

Security researchers at iDefense, among the first to detail the issue publicly, issued an advisory to address the heap overflow problem specifically. Using the vulnerability, attackers could execute arbitrary code in the context of the individual currently logged onto the device.

The security company reported that the problem specifically exists in Reals handling of the “chunked” Transfer-Encoding method, which breaks the file a server is sending into pieces.

iDefense said there are multiple ways of triggering the vulnerability, each of which result in a heap overflow.

The company also offered a workaround for users of Reals affected products, which involves the disablement of certain Active X controls in the software.

iDefense said that to successfully exploit an end users device, an attacker would need to first lure the individual into clicking on a link to a server under the outsiders control. As a result, the company advised Real users to be on the lookout for malicious links and not to visit unknown Web sites.

Advertisement

Real dealt with a slew of serious security vulnerabilities in its programs at the end of 2005, releasing multiple updates to help its customers protect themselves against outside attacks.

/zimages/3/28571.gifCheck out eWEEK.coms for the latest security news, reviews and analysis. And for insights on security coverage around the Web, take a look at eWEEK.com Security Center Editor Larry Seltzers Weblog.

Matt Hines

Matt Hines

Content Writer
eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。