Jump to content

Realnetworks Warns Of Media Player Flaws


Recommended Posts

RealNetworks' media player software contains vulnerabilities that could let an attacker take control of a PC on which the software is used to download multimedia files, the company confirms.

Corrupt files posing as normal music and video files could allow an attacker to gain control of the downloader's computer, the company says. However, RealNetworks stresses in a statement that, as far as it is aware, this has not yet happened.

There are three vulnerabilities: files could be created that will open a Web site on the user's browser, from where remote javascript can be operated; files could be created that let the attacker download and use their code on a user's machine; or media files can be created that will create buffer overrun errors.

Updates Available

The problems have been fixed, and users are advised to download updates from the company's site, it says.

The affected software is: RealOne Player, RealOne Player v2 for Windows only (all languages), RealOne Player 8, RealPlayer 10 Beta (English only), and RealOne Enterprise Desktop or RealPlayer Enterprise (all versions, standalone and as configured by the RealOne Desktop Manager or RealPlayer Enterprise Manager).

The vulnerabilities were discovered in December by Next Generation Security Software (NGSS), in Sutton, England. RealNetworks responded reasonably quickly to the discovery, a spokesperson for NGSS says.

"Some vendors take up to a year," he says.

Source: Yahoo News

Link to comment
Share on other sites

Good for them.

I don't use realplayer, but I'm willing to encourage any software company to try and look after their product with some expediency. Unlike some other company.

Link to comment
Share on other sites

Pretty honorable to announce their own deficiences and to try and correct them. RealPlayer has gotten better over time... (But as a Macster, I use ITunes)

Link to comment
Share on other sites

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Our picks

    • Wait, Burning Man is going online-only? What does that even look like?
      You could have been forgiven for missing the announcement that actual physical Burning Man has been canceled for this year, if not next. Firstly, the nonprofit Burning Man organization, known affectionately to insiders as the Borg, posted it after 5 p.m. PT Friday. That, even in the COVID-19 era, is the traditional time to push out news when you don't want much media attention. 
      But secondly, you may have missed its cancellation because the Borg is being careful not to use the C-word. The announcement was neutrally titled "The Burning Man Multiverse in 2020." Even as it offers refunds to early ticket buyers, considers layoffs and other belt-tightening measures, and can't even commit to a physical event in 2021, the Borg is making lemonade by focusing on an online-only version of Black Rock City this coming August.    Read more...
      More about Burning Man, Tech, Web Culture, and Live EventsView the full article
      • 0 replies
    • Post in What Are You Listening To?
      Post in What Are You Listening To?
    • Post in What Are You Listening To?
      Post in What Are You Listening To?
    • Post in What Are You Listening To?
      Post in What Are You Listening To?
    • Post in What Are You Listening To?
      Post in What Are You Listening To?
×
×
  • Create New...