Author Topic: Serious security hole plugged in RealPlayer  (Read 4484 times)

0 Members and 1 Guest are viewing this topic.

Offline FreewheelinFrank

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 4872
  • I'm a GNU
    • Don't Surf in the Nude!
Serious security hole plugged in RealPlayer
« on: June 28, 2007, 10:06:54 AM »
Quote
RealNetworks has patched a vulnerability in its RealPlayer and HelixPlayer software that made it possible for attackers to run arbitrary code on a victim's machine. The security hole affects applications running on Windows, Mac and Linux platforms.

The vulnerability exists within the code that handles time formats for a feature in the applications that acts as a wall clock, according to iDefense Labs, which first discovered the flaw. An attacker can exploit the vulnerability by effecting a stack-based buffer overflow that allows for the execution of malware.

The gaping hole has been plugged, but you'd never know it from browsing the RealPlayer blog or the company's security advisories. That's unfortunate. Given the severity of the vulnerability, the updates - available here for RealPlayer and here for HelixPlayer - should be installed immediately.

RealNetworks spokesman Matt Graves said the lack of disclosure is the result of the company not knowing the iDefense advisory was going to be issued on Wednesday. The company is scrambling to add an advisory to its own website. (It is unclear if a messaging system within the applications warns users of the vulnerability.)

To exploit the flaw, an attacker would first have to prompt a user to open a specially crafted SMIL file. Simply luring a RealPlayer or HelixPlayer user to a booby-trapped website is sufficient for accomplishing this. SMIL files are written in an XML markup language that uses the Synchronized Multimedia Integration Language used to code things such as for timing, layout, animations, visual transitions, and media embedding.

The vulnerability has been confirmed in version 10 and 10.5-GOLD of RealPlayer for Windows, version 10 of RealPlayer for Mac, RealPlayer Enterprise and and HelixPlayer, an open source version of RealPlayer for Linux. Earlier versions of those programs are presumed susceptible as well, according to to iDefense. ®

http://www.theregister.co.uk/2007/06/28/realplayer_security_hole_plugged/
     Bambleweeny 57 sub-meson brain     Don't Surf in the Nude Blog

drhayden1

  • Guest
Re: Serious security hole plugged in RealPlayer
« Reply #1 on: June 28, 2007, 11:32:39 AM »
thanks FWF-but the download link is for realplayer 11 beta-is that the one to download or is there a final version to download that isn't affected ??? ;)
http://realplayer.com/  The new RealPlayerBETA

Offline FreewheelinFrank

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 4872
  • I'm a GNU
    • Don't Surf in the Nude!
Re: Serious security hole plugged in RealPlayer
« Reply #2 on: June 28, 2007, 12:58:58 PM »
The only download available is a Beta. Better a secure beta than the insecure old product, I thought. Seems to work OK.
     Bambleweeny 57 sub-meson brain     Don't Surf in the Nude Blog

drhayden1

  • Guest
Re: Serious security hole plugged in RealPlayer
« Reply #3 on: June 28, 2007, 01:01:52 PM »
ok thanks FWF-i uninstalled the old one first and then installed the beta 11 8)

click to enlarge ;)
« Last Edit: June 28, 2007, 01:41:00 PM by drhayden1 »

drhayden1

  • Guest
Re: Serious security hole plugged in RealPlayer
« Reply #4 on: June 28, 2007, 01:40:44 PM »
working fine-no problems :)
know anything about the final release of realplayer 11 ???

Offline FreewheelinFrank

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 4872
  • I'm a GNU
    • Don't Surf in the Nude!
Re: Serious security hole plugged in RealPlayer
« Reply #5 on: June 28, 2007, 01:54:30 PM »
Quote
know anything about the final release of realplayer 11

Probably be announced here:

http://rws-blog.rhapsody.com/realplayer/

Seems there are some bugs with RealPlayer under Vista.

http://rws-blog.rhapsody.com/realplayer/2007/06/new-realplayer-.html
     Bambleweeny 57 sub-meson brain     Don't Surf in the Nude Blog

drhayden1

  • Guest
Re: Serious security hole plugged in RealPlayer
« Reply #6 on: June 28, 2007, 03:10:41 PM »
ok thanks FWF-if you hear first hand when its coming out-let me know ;)
my helper with keeping the screen free of bugs-seems like the only thing on the computer that can be kept bug free ;D

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Serious security hole plugged in RealPlayer
« Reply #7 on: June 29, 2007, 03:47:05 AM »
Shame on Real... Maybe it's time to use only JetAudio and not this kind of problematic Real player.
By the way, this company is being more and more associated to adult sites (at least on my country) a known source of malware. It's being blocked by WebShield or by K9 filter.
The best things in life are free.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89379
  • No support PMs thanks
Re: Serious security hole plugged in RealPlayer
« Reply #8 on: June 29, 2007, 04:38:03 PM »
I have to say I ditched Real some time ago, I hate the way it wants to take over your computer and the world when you install it and when you update it, well it tries again to set itself as default, etc.

I use JetAudio and the Real Alternative plug-in to view/listen to real audio/video format.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.6.6121 (build 24.6.9241.848) UI 1.0.809/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33939
  • malware fighter
Re: Serious security hole plugged in RealPlayer
« Reply #9 on: June 29, 2007, 04:44:09 PM »
Hi DavidR,

For some time I now use the vlc media player, and I can say it is not bad, not bad at all.
http://www.videolan.org/vlc/

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89379
  • No support PMs thanks
Re: Serious security hole plugged in RealPlayer
« Reply #10 on: June 29, 2007, 05:00:16 PM »
Thanks, but it doesn't support real video files and reports only partial support for real audio files (what ever they mean by partial). So there wouldn't be much point switching if you had to use another player for real files.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.6.6121 (build 24.6.9241.848) UI 1.0.809/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Sesame

  • Guest
Re: Serious security hole plugged in RealPlayer
« Reply #11 on: July 01, 2007, 03:02:28 PM »
(Spotting the national flag on the profiles of FWF and DavidR), BBC prefers real video files, which I  use only for the site.  For this reason, I go for Real Alternative, too.  ;)

I have VLC portable, which can play almost everything even on the move, though.  For machines on which I can take control enough to install, VLC is somehow unstable compared with JetAudio, IMO.