Welcome to P2PNET.net - The original daily p2p and digital news site. Always First!
Register | Login
RIAA News
Cool Stuff
MPAA News
Games / Consoles
News
Music
Movies
TV
Open Source
Mobiles
Advertising
Product News
P2P
Off Topic
Freedom
Politics
Interviews
Security
DRM
Links
Kids and Kartels
Search: 
Search
 
Web P2PNET   
Search: 
Search
Torrent Site Tracker
Teksavvy
 
Add real-time p2pnet headlines to YOUR site ! Click here to download our newsfeed code
p2pnet - rss feed: http://p2pnet.net/p2p.rss | p2pnet celebrities: http://p2pnet.net/celeb.rss | Mobile? http://p2pnet.net/index-wml.php

Critical RealPlayer security hole

p2p news / p2pnet:- Real Networks’ RealPlayer download application has been plagued by critical security holes, and now another has turned up.

A remotely and locally exploitable vulnerability has been identified in Realplayer and Helix Player, which could be used by hackers to execute arbitrary commands, says FrSIRT Advisory.

“This issue is due to a format string error when processing a specially crafted ‘.rp’ (relpix) or ‘.rt’ (realtext) file, which could be exploited by an attacker to take complete control of an affected system by convincing a user to open a malformed rp/rt file,” it says, going on:

“The exploit code will execute a remote shell under the permissions of the user running the media player, and effects all versions of RealPlayer and Helix Player.”

FrSIRT says it’s not aware of any official supplied patch for the hole.

Something you think we should know? tips[at]p2pnet.net

See:-
plagued - RealNetworks danger warning, June 24, 2005
FrSIRT Advisory - Realplayer and Helix Player Remote Format String Vulnerability, September 26, 2005

HOME

One Response to “Critical RealPlayer security hole”

  1. Reader's Write Says:

    Does this vulnerability apply to real alternative?

Leave a Reply

    Advertisments
MP3rocket