| 

RealPlayer update fixes security vulnerabilities

  • Post author: Omid Farhang
  • Post published: May 17, 2012
  • Reading Time: 1 min
  • Word Count: 163 words

The H-Online: RealNetworks is warning users about multiple security vulnerabilities in its RealPlayer media player application for Windows; the company says that none of the, now fixed, holes are known to have been used to compromise systems. The released update, version 15.0.4.53 of RealPlayer, closes three security holes. One hole is related to ASM RuleBook parsing that could be exploited by an attacker to remotely execute arbitrary code, another is a memory corruption problem related to MP4 file handling in the QuickTime plugin used by RealPlayer, and the third is a buffer overrun in the Media parser. ...

Continue Reading RealPlayer update fixes security vulnerabilities

RealPlayer update closes critical holes

  • Post author: Omid Farhang
  • Post published: February 7, 2012
  • Reading Time: 1 min
  • Word Count: 195 words

The H-Online: RealNetworks has released an update to RealPlayer to close a number of holes in its media player application. Version 15.02.71 of RealPlayer addresses a total of seven remote code execution vulnerabilities, rated as highly critical by Secunia, which could be exploited by an attacker to compromise a victim’s system. These include errors when processing RMFF Flags, VIDOBJ_START_CODE and RealAudio coded_frame_size, as well as RV10 Encoded Height/Width, RV20 Frame Size Array and RV40 content. A remote code execution problem in Atrac Sample Decoding has also been fixed but is not found in the 15.x.x branch of the media player; this issue affects Mac RealPlayer 12.0.0.1701 but is reportedly not found in version 12.0.0.1703. ...

Continue Reading RealPlayer update closes critical holes

RealPlayer Security Updates Published

  • Post author: Omid Farhang
  • Post published: October 18, 2010
  • Reading Time: 1 min
  • Word Count: 49 words

RealNetworks, Inc. have published product upgrades addressing vulnerabilities in RealPlayer SP 1.1.4 and earlier. The vulnerabilities may allow an attacker to execute arbitrary code. Windows users of RealPlayer SP 1.1.4 and earlier are advised to upgrade to the latest version here For more information, visit RealNetworks’ security advisory here

Continue Reading RealPlayer Security Updates Published