High-priority patch fixes critical vulns in RealPlayer
Available in Windows, Mac and Linux
Posted in Enterprise Security, 25th July 2008 22:30 GMT
Free whitepaper – Securing your online data transfer with SSL
RealNetworks has issued an update that patches four security holes in its RealPlayer jukebox program, including a critical flaw that vulnerability tracker Secunia published today.
The company says versions for Windows, Mac, Linux operating systems are all vulnerable to at least one of the flaws and that users should update as soon as possible.
Among the bugs that are fixed is a flaw within the handling of frames in Shockwave Flash (SWF) files that can be triggered by a heap-based buffer overflow. Secunia published this advisory warning of the vulnerability, which carries the common vulnerability and exposure designation CVE-2007-5400.
A second bug, CVE-2007-1309, affects the RealAudioObjects.RealAudio ActiveX control, which doesn't properly manage memory for the Console property, allowing the remote execution of code. Details weren't yet available about the remaining two vulnerabilities, CVE-2008-3064 and CVE-2008-3066.
RealNetworks thanked Dyon Balding, Elazar Broad, CERT/CC, Haifei Li and Peter Vreugdenhil (working with TippingPoint) for bringing the vulnerabilities to its attention.
The advisory is here. ®


The future of SaaS and IT infrastructure management
The mandate for application security
Extended Validation SSL Certificates
Avoiding 7 common mistakes of IT security compliance
The best practices guide for application security
Google cloud told to encrypt itself
Chinese firm hits back at cyberspy claims
BlockMaster SafeStick hardware-encrypted USB drive