TCH-Thomas Posted October 22, 2007 Share Posted October 22, 2007 From: Secunia secunia.com/advisories/27248/ Rating: Extremely critical Description: A vulnerability has been reported in RealPlayer, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to a signedness error in MPAMedia.dll when handling playlist names. This can be exploited to cause a stack-based buffer overflow by e.g. importing a file into a specified playlist with an overly long name via the RealPlayer IERPCtl ActiveX control (ierpplug.dll). Successful exploitation allows execution of arbitrary code. NOTE: The vulnerability is currently being actively exploited. Solution: Apply patch for RealPlayer 10.5 and 11 beta: service.real.com/realplayer/security/191007_player/en/securitydb.rnx Quote Link to comment Share on other sites More sharing options...
Bob Crabb Posted October 22, 2007 Share Posted October 22, 2007 Yikes!!! Thanks for the info Thomas. Quote Link to comment Share on other sites More sharing options...
TCH-Bruce Posted October 22, 2007 Share Posted October 22, 2007 Thanks for the info Thomas Quote Link to comment Share on other sites More sharing options...
Jeren Posted October 22, 2007 Share Posted October 22, 2007 So who uses RealPlayer, anyways? Good catch on the bug, at least. Thanks. Quote Link to comment Share on other sites More sharing options...
TCH-Thomas Posted October 22, 2007 Author Share Posted October 22, 2007 Probably a lot that don´t know there are alternatives. Quote Link to comment Share on other sites More sharing options...
phatfunkjazz Posted October 23, 2007 Share Posted October 23, 2007 Probably a lot that don´t know there are alternatives. What are some good alternatives for RealPlayer? Stefan Quote Link to comment Share on other sites More sharing options...
TCH-Thomas Posted October 23, 2007 Author Share Posted October 23, 2007 Personally I am using the K-Lite Mega Codec Pack found on codecguide.com. I don´t know if it´s a great replacement for everything realplayer related but they seems to update it pretty often. On the same page, I found QT Lite (Quick time alternative) and it works fine too. Quote Link to comment Share on other sites More sharing options...
phatfunkjazz Posted October 24, 2007 Share Posted October 24, 2007 Personally I am using the K-Lite Mega Codec Pack found on codecguide.com. I don´t know if it´s a great replacement for everything realplayer related but they seems to update it pretty often. On the same page, I found QT Lite (Quick time alternative) and it works fine too. hmm...I already use K-Lite Codec Pack Standard with Media Player Classic. I'll check out some of the alternatives; I've rarely use RealPlayer, but have had it so many years I never think about it. Thanks for the info. Stefan Quote Link to comment Share on other sites More sharing options...
TCH-Thomas Posted October 26, 2007 Author Share Posted October 26, 2007 Don´t know if these are new vulnerabilities or the same ones I posted about originally but being worded differently or if it´s some new vulnerabilities: secunia.com/advisories/27361/ Quote Link to comment Share on other sites More sharing options...
TCH-Bruce Posted October 26, 2007 Share Posted October 26, 2007 Thanks again Thomas Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.