TCH-Thomas Posted October 22, 2007 Posted October 22, 2007 From: Secunia secunia.com/advisories/27248/ Rating: Extremely critical Description: A vulnerability has been reported in RealPlayer, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to a signedness error in MPAMedia.dll when handling playlist names. This can be exploited to cause a stack-based buffer overflow by e.g. importing a file into a specified playlist with an overly long name via the RealPlayer IERPCtl ActiveX control (ierpplug.dll). Successful exploitation allows execution of arbitrary code. NOTE: The vulnerability is currently being actively exploited. Solution: Apply patch for RealPlayer 10.5 and 11 beta: service.real.com/realplayer/security/191007_player/en/securitydb.rnx Quote
Jeren Posted October 22, 2007 Posted October 22, 2007 So who uses RealPlayer, anyways? Good catch on the bug, at least. Thanks. Quote
TCH-Thomas Posted October 22, 2007 Author Posted October 22, 2007 Probably a lot that don´t know there are alternatives. Quote
phatfunkjazz Posted October 23, 2007 Posted October 23, 2007 Probably a lot that don´t know there are alternatives. What are some good alternatives for RealPlayer? Stefan Quote
TCH-Thomas Posted October 23, 2007 Author Posted October 23, 2007 Personally I am using the K-Lite Mega Codec Pack found on codecguide.com. I don´t know if it´s a great replacement for everything realplayer related but they seems to update it pretty often. On the same page, I found QT Lite (Quick time alternative) and it works fine too. Quote
phatfunkjazz Posted October 24, 2007 Posted October 24, 2007 Personally I am using the K-Lite Mega Codec Pack found on codecguide.com. I don´t know if it´s a great replacement for everything realplayer related but they seems to update it pretty often. On the same page, I found QT Lite (Quick time alternative) and it works fine too. hmm...I already use K-Lite Codec Pack Standard with Media Player Classic. I'll check out some of the alternatives; I've rarely use RealPlayer, but have had it so many years I never think about it. Thanks for the info. Stefan Quote
TCH-Thomas Posted October 26, 2007 Author Posted October 26, 2007 Don´t know if these are new vulnerabilities or the same ones I posted about originally but being worded differently or if it´s some new vulnerabilities: secunia.com/advisories/27361/ Quote
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.