stargeek
PHP news website logo.
home    PHP scripts    articles    seo tools    links    search    contact    shop    realtors


Patches issued for critical RealPlayer flaws







Patches issued for critical RealPlayer
flaws

Patches issued for critical RealPlayer
flaws
06/24/2005 06:55 PM

RealNetworks has issued patches to four vulnerabiliites in its RealPlayer media software, some of which could allow an attacker to run unauthorized code on the user's computer.

The most serious of the bugs, which affects RealPlayers on the Windows, Macintosh and Linux operating systems, takes advantage of a bug in the RealText file format that is used in SMIL (Synchronized Multimedia Integration Language) files, according to Michael Sutton, director of iDefense's labs. "This is something that somebody could be vulnerable to without really taking much action. They could double click on a file, or go to a URL that somebody sent them in an mail."

Sutton has not yet seen anyone publicly release software that could take advantage of any of the four bugs, but researchers at iDefense labs in Reston, Va., have privately developed code that exploits the RealText vulnerability.

The other RealPlayer flaws could be triggered by malicious code inserted into MP3, AVI, (audio video interleaved) or RM (real media) files, and affect only the Windows version of RealPlayer, according to an advisory issued by RealNetworks.

Version 3 of the Rhapsody player for RealNetworks's online music service is also affected by one of the vulnerabilities, RealNetworks said.

More information on the vulnerabilities can be found here: http://service.real.com/help/faq/security/050623_player/EN/

SEE ALSO:

  • Security concerns to stunt e-commerce growth
  • Alleged UK bank scammer still at large
  • ADVERTISEMENT
    Sun Microsystems
    See what Sun and AMD do for Wall Street. sun.com/share




    This is a GrokNews Entry: (what is grok?)





    Similar Items

    Patches issued for critical RealPlayer flaws

    Grok Headline matches for Patches issued for critical RealPlayer flaws

    Symantec patches critical firewall flaws


    Symantec patches critical firewall flaws 05/13/2004 09:35 AM
    ZDNet May 13 2004 1:36PM GMT

    Microsoft patches three critical browser
    flaws


    Microsoft patches three critical browser
    flaws
    07/30/2004 03:44 PM
    The software giant hopes that the trifecta of fixes will lasso the Download.Ject Trojan horse.

    Symantec patches four critical firewall
    flaws


    Symantec patches four critical firewall
    flaws
    05/13/2004 09:40 AM

    Real Patches Critical Media Player Flaws


    Real Patches Critical Media Player Flaws 06/11/2004 02:49 PM

    Real Patches Critical Media Player Flaws
    (PC World)


    Real Patches Critical Media Player Flaws
    (PC World)
    06/11/2004 09:49 AM
    PC World - Security holes could allow attackers to run malicious code.

    RealPlayer flaws open PCs up to
    hijackers


    RealPlayer flaws open PCs up to
    hijackers
    02/10/2004 03:01 AM

    Critical flaw discovered in RealPlayer


    Critical flaw discovered in RealPlayer 05/19/2004 04:17 PM

    Warning issued on new IE flaws


    Warning issued on new IE flaws 06/14/2004 10:16 AM
    Personal Computer World Jun 14 2004 2:23PM GMT

    RealPlayer Flaws Trigger PC Hijack Alert


    RealPlayer Flaws Trigger PC Hijack Alert 06/24/2005 07:40 PM
    Four remotely exploitable flaws in the widely deployed media player could put millions of users at risk of PC takeover attacks, RealNetworks warns.

    Patches slapped on serious PHP flaws


    Patches slapped on serious PHP flaws 12/19/2004 03:03 PM
    ZDNet Dec 18 2004 12:18AM GMT

    Apple patches Mac OS X flaws


    Apple patches Mac OS X flaws 03/22/2005 04:51 PM
    ZDNet Mar 22 2005 3:05AM GMT

    Apple Patches 15 Mac OS X Flaws


    Apple Patches 15 Mac OS X Flaws 09/08/2004 11:09 AM
    Apple claims most users are protected from the worst dangers of the flaws, many of which originate in the OS' open-source components.

    Red Hat patches critical hole


    Red Hat patches critical hole 04/04/2005 07:10 PM
    Red Hat is warning enterprise Linux users to update their installations of XFree86 to fix a number of serious security bugs, some of which could allow attackers to take over a system.

    Cisco Patches IOS Security Flaws


    Cisco Patches IOS Security Flaws 04/11/2005 07:37 PM
    The most serious vulnerability could allow malicious hackers to access network resources.

    Apple patches security flaws


    Apple patches security flaws 03/24/2005 12:14 PM
    Apple Computer has patched nine security flaws in a new update for its Mac OS X operating system, including some that could allow an attacker to take over a system, and a phishing flaw in Safari that was recently fixed in the Mozilla Firefox browser.

    Microsoft releases patches to fix 20
    flaws


    Microsoft releases patches to fix 20
    flaws
    04/13/2004 11:46 PM
    Microsoft today released fixes for 20 vulnerabilities, several of which are rated critical, in a wide range of products, including the latest Windows Server 2003 software.

    MICROSOFT Patches New Windows Flaws


    MICROSOFT Patches New Windows Flaws 06/08/2004 04:59 PM
    “Microsoft released software updates for versions of Windows XP and Windows Server 2003 and warned customers about a security vulnerability in a Windows component called IDirectPlay4, which is used to support multiplayer network games.The security hole, if successfully exploited, could allow a remote attacker to cause a Windows application using the affected component to fail, creating a denial of service attack.”Read more…

    Microsoft patches a pair of flaws


    Microsoft patches a pair of flaws 06/08/2004 03:17 PM

    Apple: Patches for older OS X flaws


    Apple: Patches for older OS X flaws 10/31/2003 04:05 PM
    ZDNet Oct 31 2003 3:10PM ET

    Microsoft release five critical patches


    Microsoft release five critical patches 04/14/2005 04:17 AM
    IT Vibe Apr 14 2005 8:31AM GMT

    Oracle issues critical patches


    Oracle issues critical patches 04/16/2005 02:44 AM
    OptusNet Apr 16 2005 6:16AM GMT

    Apple patches critical Mac OS X hole


    Apple patches critical Mac OS X hole 05/24/2004 04:29 AM
    'Theoretical vulnerability'

    Critical flaws plague Kerberos


    Critical flaws plague Kerberos 09/02/2004 08:15 AM
    ZDNet Sep 2 2004 12:09PM GMT

    New Critical Flaws Discovered in Windows


    New Critical Flaws Discovered in Windows 12/30/2004 06:28 AM
    http://www.wininformant.com/inc/images/WinInfo/security_temperature.gi f

    Microsoft warns of critical flaws


    Microsoft warns of critical flaws 07/15/2004 05:17 AM
    Windows users are being urged to update their PCs after critical flaws were found in some Microsoft programs.

    US-CERT: Critical Flaws in libpng


    US-CERT: Critical Flaws in libpng 08/05/2004 10:21 AM
    Multiple vulnerabilities in the popular PNG reference library puts users at risk of malicious hacker attacks.

    Critical flaws in IE and Outlook
    discovered


    Critical flaws in IE and Outlook
    discovered
    04/01/2005 12:12 PM
    Vulnerabilities allow for remote code execution, creating the potential for attackers to install backdoor Trojans.

    Microsoft Preps Patches for 'Critical'
    Flaws


    Microsoft Preps Patches for 'Critical'
    Flaws
    01/06/2005 07:26 PM
    The company's first monthly security patch rollout for 2005 will comprise three Windows fixes; the maximum severity rating is "critical."

    Symantec Patches 'High Risk' Flaws


    Symantec Patches 'High Risk' Flaws 12/31/2004 02:12 PM
    Vulnerabilities in Nexland Firewall appliances put users at risk of security bypass, manipulation of data and denial-of-service attacks.

    Microsoft releases patches for Windows
    flaws


    Microsoft releases patches for Windows
    flaws
    04/15/2004 12:58 PM
    CNN Apr 15 2004 5:39PM GMT

    Microsoft Patches New Windows Flaws (PC
    World)


    Microsoft Patches New Windows Flaws (PC
    World)
    06/08/2004 03:14 PM
    PC World - Moderate security vulnerabilities found in XP, Windows Server 2003.

    Microsoft releases patches for 18
    separate flaws


    Microsoft releases patches for 18
    separate flaws
    04/12/2005 05:23 PM
    Microsoft today released eight security bulletins detailing fixes for 18 separate vulnerabilities affecting a wide range of its software products.

    Symantec patches more Norton AntiVirus
    flaws


    Symantec patches more Norton AntiVirus
    flaws
    03/31/2005 03:28 AM
    ZDNet Australia Mar 31 2005 7:05AM GMT

    Microsoft releases new patches for
    Windows flaws


    Microsoft releases new patches for
    Windows flaws
    04/13/2004 06:24 PM
    SiliconValley.com Apr 13 2004 11:09PM GMT

    Apple Patches 15 Mac OS X Flaws (Ziff
    Davis)


    Apple Patches 15 Mac OS X Flaws (Ziff
    Davis)
    09/08/2004 11:01 AM
    Ziff Davis - Apple claims most users are protected from the worst dangers of the flaws, many of which originate in the OS' open-source components.

    Microsoft patches "critical" Windows
    security bug


    Microsoft patches "critical" Windows
    security bug
    02/11/2004 12:12 PM
    Microsoft issues a patch for a critical eight-month-old vulnerability. Why did it take so long?

    Microsoft Readies Critical Software
    Patches


    Microsoft Readies Critical Software
    Patches
    04/09/2005 01:16 PM
    PC World Online Apr 9 2005 4:37PM GMT

    Critical Microsoft patches coming next
    week


    Critical Microsoft patches coming next
    week
    04/08/2005 10:07 AM
    Microsoft on Tuesday plans to issue eight security alerts with patches, some critical, for Windows, Office, MSN Messenger, and Exchange, it said Thursday.

    "Microsoft patches three critical
    security problems"


    "Microsoft patches three critical
    security problems"
    11/12/2003 01:21 PM

    Grok Description matches for Patches issued for critical RealPlayer flaws
    GrokA matches for Patches issued for critical RealPlayer flaws

    Patches issued for critical RealPlayer flaws

    The following phrases have been identified by the grok system as matching this entry:

















    Also check out:


    Grok

    Ipod Porn on the
    Rise

    Brief Abstract of
    Wikipedia's
    Mesothelioma Cancer
    page

    Get first aid
    instructions in your
    cell phone

    IE is crap
    JSPWiki gains
    podcasting support

    IBM ruffles workers
    by expanding India
    staff

    Alleged UK bank
    scammer still at
    large

    JavaOne: Java spec
    promises better
    mobile experience

    Microsoft to ship
    Longhorn with RSS

    US senators offer
    bill to protect
    municipal broadband

    IBM to offer tools
    tryouts

    Security concerns to
    stunt e-commerce
    growth

    New interview
    Ah fair use, where
    would we be without
    you?

    links for 2005-06-23
    links for 2005-06-24
    Sun's new new new
    Java nomenclature

    AMD: you lose some,
    you win some

    Nsite launching free
    online ERP tools

    ChoicePoint overhaul
    falls behind

    The girl with the
    DVD face

    Dock Ellis,
    psychedelic pitcher

    R.I.P. Bennie
    Schriever

    Xeni on NPR: SAG
    rejects video game
    industry's contract
    offer -- UPDATED

    Futuristic 1960s
    Lambretta ad

    Banned Nepali radio
    station transmits
    via megaphone

    Lego journal
    launches

    Sat photos document
    razing of 200k
    person shantytown in
    Zimbabwe

    Vertical Farming:
    High-rise urban mass
    agriculture

    Heinlein's house
    Cory speaking at
    MacHack Detroit,
    July 27-31

    Lost malls of the
    50s and 60s

    Scientology's
    E-Meters reviewed

    Gummed magnetic tape
    on rolls

    Queen Liz: Sony
    remotes are too hard
    to use

    Kickass Kung Fu:
    Like Dance Dance
    Revolution for
    martial artists

    Chocolate sneakers
    Web zen: TV zen
    USB-powered mini
    lava-lamp

    Bluetooth pistol
    mouse

    NES misbegotten
    tchotchkes

    Protecting yourself
    against moving
    company scammers

    Dead frog found in
    salad

    Daniel Clowes on NPR
    Clickwheel brings
    comics, animation to
    iPod

    Homer Simpson
    Computer Key Car

    Sweaty men like
    Men's Health

    Secret CIA
    conspiracy revealed
    on abandoned car

    Photographer's
    Railroad Page

    Dianne Feinstein on
    the Broadcast Flag:
    Idiot or liar?

    Schneier on
    Security: Talking to
    Strangers

    Religious Gadget
    Thursday: The
    E-Meter : Gizmodo

    Damaging 'Deference'
    Michael J. Totten:
    Extremists and Their
    Hallucinations

    as is clear from
    Foley's "apology,"

    what is grok?