RealPlayer Still Vulnerable to Attack

RealPlayer Still Vulnerable to Attack

Written By
Dennis Fisher
Dennis Fisher
Dec 3, 2002
1 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Nearly two weeks after posting a faulty patch for several security vulnerabilities in its ubiquitous RealPlayer and RealOne software, Real Networks Inc. has yet to release a working fix for the problems.

And, a security researcher said Tuesday that he has discovered five more vulnerabilities in the media players.

Mark Litchfield of Next Generation Security Software Ltd., who also discovered the three original Real flaws, said he has found five additional vulnerabilities in the RealPlayer and RealOne players. All of the new issues are buffer overruns and can be exploited remotely via code embedded in e-mail messages.

Litchfield has notified Real of some of the flaws and is currently in the process of writing proof-of-concept exploit code for the others before sending them to the Seattle-based company. He is working with Real Networks on fixes for the vulnerabilities.

The three vulnerabilities Litchfield identified last month are also buffer overruns, and an attacker exploiting one of them would be able to run code in the security context of the logged-on user. Real Networks released a patch for these vulnerabilities on Nov. 21, but later removed it from its Web site after Litchfield discovered it didnt entirely fix the flaws.

The RealPlayer and its newer cousin, RealOne, have more than 250 million registered users combined and are used widely in the enterprise as well as the consumer market.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.