On last.fm: Taylor Swift photos and free music!
BNET Business Network:
BNET
TechRepublic
ZDNet

By Joris Evers
Posted on ZDNet News: Jun 24, 2005 12:44:00 AM

Several security holes in RealNetworks' widely used media player software could put PCs at risk of attack, the company has warned.

Four vulnerabilities in RealPlayer have been discovered, the most serious of which could allow an intruder to gain control of a computer, RealNetworks said in a security advisory posted Thursday. Software updates are now available to plug the holes, the company said.

Security experts from the French Security Incident Response Team, or FrSIRT, labeled the problems as "critical"--the highest rating--in an alert issued Thursday.

The problems exist in current and some older releases of RealPlayer, and they affect versions for Windows as well as Mac OS and Linux, RealNetworks said. In addition, one of the newly patched bugs also is found in Rhapsody 3, the software used in RealNetworks' music service.

Three of the four flaws could be exploited using a malicious media file, RealNetworks said. Specially crafted RealMedia and AVI files could allow an attacker to take over a user's computer, while a malicious MP3 file could be used to overwrite local files or execute ActiveX controls, it said.

To take advantage of the fourth flaw, a hacker would need to build a malicious Web site. However, the attack would require the user to be running earlier versions of Internet Explorer with standard settings on the computer, RealNetworks said.

RealNetworks' updates are available in its advisory for all affected products and recommends that people install the newer versions.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 4 Talkback(s)
Pathetic...
... the only ones using Real are the outfits looking for flaws.

Well, and organizations who employ someone trying to avoid Microsoft wherever possible.

And a few unsophisticated people w... (Read the rest)
Posted by: Anton Philidor Posted on: 06/25/05 You are currently: a Guest | | Terms of Use
Shouldn't be a big problem.  mustangj36@... | 06/23/05
IF we have to install or use Real  FilledOut | 06/24/05
Yeah, and it doesn't...  Colonel_Panic | 06/24/05
Pathetic...  Anton Philidor | 06/25/05

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads