More Vulnerabilities Found; More Platforms Affected
Severity: High
26 October, 2007
Update:
On Monday 22 October, we published an alert about a serious vulnerability that affects RealPlayer 10.5 and RealPlayer 11 beta running on Windows. By enticing one of your users to a malicious Web site, an attacker can exploit this vulnerability to execute code on your user’s computer, with your user’s privileges. In the worst case scenario, the attacker could gain total control of the victim’s PC. RealNetworks released a patch to fix that problem. However, it appears that update marked just the beginning of RealNetwork security holes.
Late yesterday, RealNetwork released the second batch of security updates this week, this time fixing six serious vulnerabilities in their media player product line. Here’s what you need to know about the new flaws.
The new flaws affect many more products than the earlier flaw did, including products that run in OS X and Linux. The affected products now include:
- RealPlayer 8, 10, 10.5, 11 for Windows, Mac, and Linux
- RealOne Player v1 and v2 for Windows, and RealOne Player for Mac
- RealPlayer Enterprise
- Helix Player 10.0.x for Linux.
Though these new flaws differ from one another technically, they share many similarities. For example, all six flaws involve buffer overflow vulnerabilities triggered when RealPlayer
…