On TechRepublic: 10 things every geek should know
BNET Business Network:
BNET
TechRepublic
ZDNet

By Michael Kanellos
Posted on ZDNet News: Apr 8, 2004 11:31:00 PM

RealNetworks has issued a patch for a security flaw in one of its plug-ins that could let an attacker gain control of computers running any of several versions of the company's popular media player software.

The problem involves a buffer overflow that affects the R3T media plug-in. For people who download the plug-in and use RealPlayer 8, RealOne Player, RealOne Player v2 for Windows, RealPlayer 10 Beta (English only) or RealPlayer Enterprise, their computer can be overpowered by an attacker, who can then insert surreptitious code and use it to execute other actions.

RealPlayer 10 Gold is not affected, the company said, because it removes the plug-in during installation.

"While we have not received reports of anyone actually being attacked with this exploit, and though the percentage of players with this plug-in is very small, all security vulnerabilities are taken very seriously by RealNetworks," the company said in a statement posted on its site this week.

Although hackers and virus writers have often focused on attacking Microsoft, other popular software programs are not immune. Executives at security companies often assert that one of the main criteria for some attackers is the size of the target audience. Real identified three similar flaws in February.

Ways to fix the flaw, and more information on it, can be found here.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 7 Talkback(s)
Limited vulnerability. RP10 is okay.
If you have RealPlayer 10 Gold, you don't have a problem.

You have a problem if you installed RealPlayer 10 Beta or an earlier version, and then used it to play the rather unusual "Rich Text 3D... (Read the rest)
Posted by: Robert Carnegie Posted on: 04/14/04 You are currently: a Guest | | Terms of Use
doesn't surprise me....  DarbyOhara | 04/09/04
And I almost installed it...  Alpha_Female | 04/09/04
I installed it back when  V Sanders | 04/09/04
Limited vulnerability. RP10 is okay.  Robert Carnegie | 04/14/04
this is exact;ly  V Sanders | 04/09/04
Another for the court case  FilledOut | 04/09/04
and then  V Sanders | 04/10/04

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads