Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

March 24th, 2011, 08:54 GMT · By

0-Day Vulnerability Announced for RealPlayer

SHARE:

Adjust text size:


Exploit code available for 0-day RealPlayer vulnerability
Enlarge picture
A critical RealPlayer vulnerability that could be exploited in drive-by download attacks has been disclosed as a zero-day.

According to Luigi Auriemma, the independent security researcher who discovered it, the flaw is a classic heap overflow in rvrender.dll that occurs when handing Internet Video Recording (IVR) files.

It is "caused by the allocation of a certain amount of data (frame size) decided by the attacker and the copying of another arbitrary amount on the same buffer," the researcher explains.

RealPlayer 14.0.2.633 for Windows is confirmed as being vulnerable, but older versions of the player, as well as those for other supported platforms, are likely vulnerable.

Luigi Auriemma is an adept of the full-disclosure vulnerability reporting philosophy, which means the developer, RealNetworks, was probably not notified in advance.

RealPlayer is a proprietary media player that gained much popularity during the '90s for being one of the first to implement media streaming capabilities.

Today its market share is fairly low because users have since moved to open source alternatives like VLC, but even so, it is still used to support RealNetworks' proprietary video and audio formats.

It's not certain when the vendor will respond with a patch because the company doesn't have a particularly great track record when it comes to providing timely fixes.

In the meantime, users can manually remove the browser plug-ins and ActiveX controls in order to close the Web attack vector.

The same day when he disclosed the RealPlayer vulnerability, Auriemma also published details and exploit code for 34 critical flaws found in several SCADA products.

Those advisories have generated quite a stir in the security community and temporarily re-launched the full disclosure vs. responsible disclosure discussion.

TELL US WHAT YOU THINK:

640 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Flurry of Critical Vulnerabilities Patched in RealPlayer

Critical RealPlayer Vulnerabilities Revealed

ZDI Discloses Vulnerabilities Vendors Failed to Resolve in Timely Manner

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM