Jump to content

Realplayer - Extreme Vulnerability Found


Recommended Posts

From: Secunia

secunia.com/advisories/27248/

 

Rating: Extremely critical

 

Description:

A vulnerability has been reported in RealPlayer, which can be exploited by malicious people to compromise a user's system.

 

The vulnerability is caused due to a signedness error in MPAMedia.dll when handling playlist names. This can be exploited to cause a stack-based buffer overflow by e.g. importing a file into a specified playlist with an overly long name via the RealPlayer IERPCtl ActiveX control (ierpplug.dll).

 

Successful exploitation allows execution of arbitrary code.

 

NOTE: The vulnerability is currently being actively exploited.

 

Solution:

Apply patch for RealPlayer 10.5 and 11 beta:

service.real.com/realplayer/security/191007_player/en/securitydb.rnx

Link to comment
Share on other sites

Personally I am using the K-Lite Mega Codec Pack found on codecguide.com. I don´t know if it´s a great replacement for everything realplayer related but they seems to update it pretty often.

 

On the same page, I found QT Lite (Quick time alternative) and it works fine too.

Link to comment
Share on other sites

Personally I am using the K-Lite Mega Codec Pack found on codecguide.com. I don´t know if it´s a great replacement for everything realplayer related but they seems to update it pretty often.

 

On the same page, I found QT Lite (Quick time alternative) and it works fine too.

 

hmm...I already use K-Lite Codec Pack Standard with Media Player Classic. I'll check out some of the alternatives; I've rarely use RealPlayer, but have had it so many years I never think about it. Thanks for the info.

 

Stefan

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

 Share

×
×
  • Create New...