On CBS.com: Victoria Secret Model Contest -Vote Now!
BNET Business Network:
BNET
TechRepublic
ZDNet

June 27th, 2007

Code execution hole haunts RealPlayer, HelixPlayer

Posted by Ryan Naraine @ 8:58 am

Categories: Botnets, Browsers, Data theft, Digital rights management, Exploit code, Hackers, Metasploit, Open source, Patch Watch, Pen testing, Responsible disclosure, Viruses and Worms, Vulnerability research, Zero-day attacks

Tags: Security, RealNetworks Inc., RealNetworks RealPlayer, iDefense, Ryan Naraine

RealNetworks has issued a security fix for a gaping hole in its flagship RealPlayer software but, strangely, the company has not issued a security advisory to warn its millions of customers.

Code execution hole haunts RealPlayer, HelixPlayer

Instead, the required warning came from the researchers at iDefense Labs who found a remotely exploitable security hole affecting both RealPlayer and HelixPlayer.

The last security warning on RealNetworks’ security page dates back to March 22, 2006.

From the iDefense advisory:

Remote exploitation of a buffer overflow within RealNetworks’ RealPlayer and HelixPlayer allows attackers to execute arbitrary code in the context of the user.

The issue specifically exists in the handling of HH:mm:ss.f time formats by the ‘wallclock’ functionality within the code supporting SMIL2. An excerpt from the code follows.

A successful exploit requires that an attacker lure a RealPlayer/HelixPlayer user to open a maliciously crafted SMIL file. This can be done by simply convincing the target to visit a malicious Web page.

iDefense said it confirmed the bug in version 10.5-GOLD of RealNetworks’ RealPlayer and HelixPlayer. Older versions are assumed to be vulnerable.

The company confirmed that RealNetworks addressed this vulnerability by releasing fixed versions of their software.

RealNetworks has not provided iDefense with any links referring to updated packages or advisories. Installing the latest version from their web site will address the vulnerability.

To ensure your RealPlayer software is patched, use the Tools menu and select Check for Update.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 6 Talkback(s)
Using Real Player's "check for updates" didn't update
The free Real Player was installed on one machine I was patching last night, so I used its "Check for Updates" feature. It "updated" to version 10.x/6.0.12.1578, which was the same version number tha... (Read the rest)
Posted by: bugmenot2 Posted on: 06/29/07 You are currently: a Guest | | Terms of Use
Who use RealPlayer anyway?  Grayson Peddie | 06/27/07
Right, but...  Ryan NaraineZDNet Moderator | 06/27/07
Well I don't use WinZip.  Grayson Peddie | 06/27/07
Where have you been hiding? Mars?  bportlock | 06/27/07
Once upon a time, I did.  James T. Kirk | 06/28/07
Using Real Player's "check for updates" didn't update  bugmenot2 | 06/29/07

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads