Jump to content
Sign in to follow this  
TCH-Thomas

Realplayer - Extreme Vulnerability Found

Recommended Posts

From: Secunia

secunia.com/advisories/27248/

 

Rating: Extremely critical

 

Description:

A vulnerability has been reported in RealPlayer, which can be exploited by malicious people to compromise a user's system.

 

The vulnerability is caused due to a signedness error in MPAMedia.dll when handling playlist names. This can be exploited to cause a stack-based buffer overflow by e.g. importing a file into a specified playlist with an overly long name via the RealPlayer IERPCtl ActiveX control (ierpplug.dll).

 

Successful exploitation allows execution of arbitrary code.

 

NOTE: The vulnerability is currently being actively exploited.

 

Solution:

Apply patch for RealPlayer 10.5 and 11 beta:

service.real.com/realplayer/security/191007_player/en/securitydb.rnx

Share this post


Link to post
Share on other sites

So who uses RealPlayer, anyways? ;)

 

Good catch on the bug, at least. Thanks.

Share this post


Link to post
Share on other sites
Probably a lot that don´t know there are alternatives.

 

What are some good alternatives for RealPlayer?

 

Stefan

Share this post


Link to post
Share on other sites

Personally I am using the K-Lite Mega Codec Pack found on codecguide.com. I don´t know if it´s a great replacement for everything realplayer related but they seems to update it pretty often.

 

On the same page, I found QT Lite (Quick time alternative) and it works fine too.

Share this post


Link to post
Share on other sites
Personally I am using the K-Lite Mega Codec Pack found on codecguide.com. I don´t know if it´s a great replacement for everything realplayer related but they seems to update it pretty often.

 

On the same page, I found QT Lite (Quick time alternative) and it works fine too.

 

hmm...I already use K-Lite Codec Pack Standard with Media Player Classic. I'll check out some of the alternatives; I've rarely use RealPlayer, but have had it so many years I never think about it. Thanks for the info.

 

Stefan

Share this post


Link to post
Share on other sites

Don´t know if these are new vulnerabilities or the same ones I posted about originally but being worded differently or if it´s some new vulnerabilities: secunia.com/advisories/27361/

Share this post


Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Sign in to follow this  

×
×
  • Create New...