You are here: silicon.com > Software > Security Strategy

Security Strategy

Real plugs Player's holes

Quartet of security flaws rated "critical"

Tags: realplayer, real

By Joris Evers

Published: 24 June 2005 09:20 GMT

Several security holes in RealNetworks' widely used media player software could put PCs at risk of attack, the company has warned.

Four vulnerabilities in RealPlayer have been discovered, the most serious of which could allow an intruder to gain control of a computer, RealNetworks said in a security advisory posted on Thursday. Software updates are now available to plug the holes, the company said.

Security experts from the French Security Incident Response Team, or FrSIRT, labelled the problems as "critical" - the highest rating - in an alert issued yesterday.

The problems exist in current and some older releases of RealPlayer, and they affect versions for Windows as well as Mac OS and Linux, RealNetworks said. In addition, one of the newly patched bugs is also found in Rhapsody 3, the software used in RealNetworks' music service.

Three of the four flaws could be exploited using a malicious media file, RealNetworks said. Specially crafted RealMedia and AVI files could allow an attacker to take over a user's computer, while a malicious MP3 file could be used to overwrite local files or execute ActiveX controls, it said.

To take advantage of the fourth flaw, a hacker would need to build a malicious website. However, the attack would require the user to be running earlier versions of Internet Explorer with standard settings on the computer, RealNetworks said.

RealNetworks' updates are available in its advisory for all affected products and recommends that people install the newer versions.

Joris Evers writes for CNET News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Nick Heath Your top HR tech priorities for next year revealed How to make human resources IT work for you

Bob Tarzey Why you must rein in your power users When they do damage, it can be catastrophic to your business


  • Jobs
Mac/PC Service Desk Analyst- Mac OS X, Windows, Adobe, Office, ARD

Mac/PC Service Desk Analyst- Mac OS X, Windows, Adobe, Office, ARDA Progressive and rapidly expanding Central London Group of Agencies are seeking to ...

MAC osx IT Support Manager - MAC / Linux /Media - 30k - London

The successful candidate will be looking after a network of around 30 MAC and Windows PCs running off a Linux Server. Technically, candidates will ...

Senior Web Developer C#, PHP, .Net, Ajax, JSON London - 35

Essential Skills* C# / .Net 2.0 / 3.5* PHP 5 * DOM Javascript and experience with Scriptaculous, Prototype or JQuery toolkits* Experience working ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: