CommunityDispatch.com
Community News and Information

Contact Us | Submit News |About Us| Subscribe | Home Page
Custom Search


search
For More Current News, Click Here

Search








Cyber Alert
RSS Feed RSS Feed
Last Updated: May 31, 2008 - 8:42:48 AM

                                                                                                                              

Cyber Alert: RealNetworks RealPlayer ActiveX Playlist Vulnerability


By U.S. CERT, Department of Homeland Security


Oct 24, 2007 - 7:36:16 PM


 

 

 

 

Cyber Security Alert SA07-297A archive

RealNetworks RealPlayer ActiveX Playlist Vulnerability

Original release date: October 24, 2007
Last revised: --
Source: US-CERT

Systems Affected

  • RealPlayer 11 beta
  • RealPlayer 10.5
  • RealPlayer 10
  • RealOne Player v2
  • RealOne Player

Overview

RealNetworks RealPlayer for Microsoft Windows contains a vulnerability that could allow an attacker to take control of your computer when you visit a malicious web site.


Solution

Upgrade and install a patch

RealNetworks has released a patch to address this vulnerability. Information about the vulnerability and the patch is available in RealPlayer Security Vulnerability and Security Update for Real Player.

  • RealPlayer 10.5 and RealPlayer 11 beta users should install the patch.
  • RealOne Player v2, and RealPlayer 10 users should upgrade to RealPlayer 10.5 or RealPlayer 11 beta and then install the patch.
Windows versions of RealPlayer 8 and earlier are not affected. Mactintosh and Linux versions of RealPlayer are not affected.

 

Disable ActiveX for untrusted web sites

 

Disabling ActiveX in the Internet Zone (or any zone used by an attacker) reduces the chances of exploitation of this and other vulnerabilities. Instructions for disabling ActiveX in the Internet Zone can be found in the "Securing Your Web Browser" document.

 

There are public reports that this vulnerability is being actively exploited.


Description

A buffer overflow in the way RealPlayer handles playlists received from an ActiveX control on a web page could allow an attacker to access your computer, install and run malicious software on your computer, or cause it to crash.

More technical information is available in US-CERT Technical Cyber Security Alert TA07-297A and Vulnerability Note VU#871673.


References


Feedback can be directed to US-CERT.

 



Cyber Alert
Latest Headlines


Domain Registrations Scam: FTC Halts Cross Border Con Artists
FBI Warns Cyber Criminals Targeting Users of EPPI Cards
FBI Warns Cyber Criminals Targeting Users of EPPICards
NASA Employee Suspended Blogging on the Clock
Scam Alert: Don't Send Money To Fake Grants And Sweepstakes Schemes
Cyber Alert: Java Sun Updates for Multiple Vulnerabilities in Java
Internet Alert: St. Valentine’s Day E-Card Carries Storm Worm Virus
Cyber Safe California Summit 2008 - March 4

security, windows update, Cyber Security Assembly