Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > other security issues & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old September 29th, 2004, 01:56 PM
the mul's Avatar
the mul the mul is offline
Very Frequent Poster
 
Join Date: Jul 2003
Location: scotland
Posts: 1,709
Default Real Player Security Vulnerabilities, Time to patch it ... again

SECUNIA ADVISORY ID: SA12672

TITLE: RealOne Player / RealPlayer / Helix Player Multiple Vulnerabilities

VERIFY ADVISORY: http://secunia.com/advisories/12672/


CRITICALITY: Highly Critical

IMPACT: System access, Manipulation of data

WHERE: From remote


SOFTWARE AFFECTED:

RealPlayer 8: http://secunia.com/product/665/
RealPlayer 10: http://secunia.com/product/2968/
RealOne Player v2: http://secunia.com/product/2378/
RealOne Player v1: http://secunia.com/product/666/
Helix Player 1.x: http://secunia.com/product/3970/
RealPlayer Enterprise: http://secunia.com/product/3342/


DESCRIPTION:

Multiple vulnerabilities have been reported in RealOne Player, RealPlayer and Helix Player, which can be exploited by malicious people to compromise a user's system and delete files.

1) An unspecified error when running local RM files can potentially be exploited to execute arbitrary code. This vulnerability has been reported in:




RealPlayer 8 / 10 / 10.5 Beta (6.0.12.1016) / 10.5 (6.0.12.1040) / Enterprise on Windows


RealOne Player v1, v2 on Windows


Mac RealPlayer 10 Beta and Mac RealOne Player


Linux RealPlayer 10 and Helix Player on Linux



2) A problem with malformed calls can be exploited to execute arbitrary code by embedding the player on a malicious website and making specially crafted calls. The vulnerability has been reported in:




RealPlayer 10 / 10.5 Beta (6.0.12.1016) / 10.5 (6.0.12.1040)


RealOne Player v1, v2 on Windows.



3) An unspecified error allows malicious websites and media files to delete arbitrary local files. The vulnerability has been reported in:




RealPlayer 10 / 10.5 Beta (6.0.12.1016) / 10.5 (6.0.12.1040)


RealOne Player v1, v2 on Windows.




SOLUTION: Apply Updates (see the original Vendor Advisory below).

ORIGINAL ADVISORY: http://www.service.real.com/help/faq...928_player/EN/


THE MUL
__________________
OUTPOST BETA TESTER

WINDOWS 7 PRO 64 BIT, SP1, DUO CORE 2 OVERCLOCKED 3.4 GHZ 4 Gb PC6400 RAM 800MHZ
AVIRA ANTIVIRUS PREMIUM 2013 - Outpost PRO 8.0(4164.652.1856) - MBAM PRO V 1.70 - WINPATROL PLUS V 26.0 - HITMAN PRO 3.7.0
  #2  
Old September 29th, 2004, 03:57 PM
Brent Brent is offline
Regular Poster
 
Join Date: Jun 2004
Posts: 71
Default Re: Real Player Security Vulnerabilities, Time to patch it ... again

I havent used Real Player in years......
__________________
For you newbs:
Get a Virus Scanner
Get SP2
Turn on Windows Firewall
Get Ad-Aware SE Personal
Get Spybot Search & Destroy
 

Wilders Security Forums > Other Security Topics > other security issues & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 08:37 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums