Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

October 19th, 2010, 07:23 GMT · By

Critical RealPlayer Vulnerabilities Revealed

SHARE:

Adjust text size:


RealPlayer SP 1.1.5 addresses critical vulnerabilities
Enlarge picture
RealNetworks has published a security advisory disclosing critical vulnerabilities in its RealPlayer line of products, many of which can be exploited to execute arbitrary code.

The problem affects versions older than RealPlayer SP 1.1.5 and RealPlayer 2.1.3 for Windows. The latest stable and unaffected version of RealPlayer SP is 1.1.5 Build 12.0.0.879, which was released at the beginning of July.

It's not clear why this advisory was published three months later, but it's a good reminder to update for users who haven't done so already.

The RealNetworks advisory lists seven security issues, but vulnerability research vendor Secunia claims that there are in fact eleven.

According to Secunia, "one has an unknown impact and others can be exploited by malicious people to compromise a user's system."

RealNetwork notes that five of the disclosed vulnerabilities affect supported RealPlayer versions up to 1.1.4 and four of them also affect RealPlayer Enterprise 2.1.2.

Five of the vulnerabilities were reported through TippingPoint's Zero Day Initiative program, four were discovered by researchers from Secunia, while two are credited to Microsoft Vulnerability Research (MSVR).

Many of the flaws can be exploited remotely through malformed audio, video or playlist files. This exposes users to drive-by download attacks.

Secunia rates the security impact of this advisory as highly critical and US-CERT also issued an alert about it, encouraging users and administrators to upgrade.

RealPlayer SP is a free multimedia player with streaming, online radio, CD burning and media organizing capabilities.

The Internet streaming feature brought it a great deal of popularity during the 90's, but for the past five years its market share dropped considerably in favor of Windows Media Player or the open source VLC.

However, some people and enterprises still use it for proprietary RealMedia formats: RealAudio (*.ra, *.rm), RealVideo (*.rv, *.rm, *.rmvb), RealPix (*.rp), RealText (*.rt), RealMedia Shortcut (*.ram, *.rmm).

The latest version of RealPlayer can be downloaded here.

TELL US WHAT YOU THINK:

1,275 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Binary Planting Vulnerability Addressed in VLC Media Player

Critical Vulnerability Fixed in VLC Media Player

Apple Patches Two Critical Vulnerabilities in QuickTime for Windows

Apple Fixes Critical Remote Code Execution Bug in QuickTime

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM