RealPlayer Patch Fails to Fix Flaws

RealPlayer Patch Fails to Fix Flaws

Written By
Dennis Fisher
Dennis Fisher
Nov 22, 2002
2 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

There are three serious flaws in the popular RealOne and RealPlayer media players that allow an attacker to run code on remote users machines.

Real Networks Inc. issued a patch for these flaws, but it was subsequently found to not fix the problem and was supposed to be removed from the companys Web site. However, as of 2:45 EST Friday, the patch was still accessible.

The company is working on another fix, which may not be available until early next week.

The first vulnerability occurs when a user clicks on a link to a SMIL (synchronized multimedia integration language) file. The Real software attempts to automatically download and play the content. But if an attacker supplied an overly long parameter within the SMIL file, this would cause a heap overflow in Realplay.exe.

The second vulnerability results when a user tries to download and play a file with an overly long filename parameter. When the user tries to play the file, a heap overflow occurs.

The third problem lies in the way the players handle some overly long file names. If a user downloaded such a file and then right-clicked in the “Now Playing” field and selected “Edit clip info” or “Select copy to my library,” it would cause a stack overflow.

An attacker exploiting these flaws would be able to run code in the context of the user, according to Mark Litchfield of Next Generation Security Software Ltd., who discovered the flaws and notified Real Networks, based in Seattle, of the problems. NGSS issued a bulletin on the problems Friday.

Litchfield also said that the RealOne Enterprise Desktop is vulnerable to the last two of these attacks.

Real on Thursday posted to its Web site an advisory and a patch for these vulnerabilities. However, after some testing, Litchfield discovered that the patch didnt fix all of the issues it was meant to address.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.