RealPlayer flaw raises security flags

Be wary of unknown files, say experts

Written by Shaun Nichols in California

Security experts are warning users to be vigilant after the disclosure of a new security vulnerability in RealPlayer.

The flaw could allow an attacker to remotely execute code on a victim's machine.

Security researcher Evgeny Legerov originally posted the vulnerability on New Year's Day, but did not specify the exact nature of the flaw.

Secunia reported in an advisory that the problem is in fact a buffer overflow error. If exploited, the error could cause an application crash which would give an attacker the ability to execute code.

Buffer overflow errors are often used by attackers to install malware. Secunia advises users to avoid opening untrusted files or visiting suspicious websites.

Security firm Sans Institute also urged users to avoid suspicious files and sites, and recommends that system administrators block access to a pair of domains which have shown a history of exploiting RealPlayer flaws.

Tags:

Further reading

Cyber-criminals launch PDF malware offensive

PDFex storms into the charts   More...

Attackers feast on Real Player flaw

Real promises to patch hole as soon as possible   More...

RealPlayer 11 allows online video capture

Users can download clips and burn them to CD or DVD   More...

Microsoft and Real agree $761m settlement

New partnership ends antitrust battle   More...

Related articles

QuickTime flaw adds to Apple's woes

Exploit especially dangerous for Firefox users   More...

Microsoft warns of new Word attacks

Remote code flaw being exploited   More...

Mozilla patches critical Thunderbird flaw

Attackers could remotely execute code on compromised systems   More...

Bug hunters make short work of Firefox

First vulnerabilities surface for new browser   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

23 Jul 2008

2.99 MBSmall time security, official 'spying' requests and a spammer jail break More...

22 Jul 2008

3.22 MBSat-nav crashes, open source security and female gamers More...

21 Jul 2008

3.12 MBGlobal internet reach, online spending and the space race More...

Poll

EUROPEAN E-COMMERCE

EUROPEAN E-COMMERCE

Are you happy making an online purchase from another European country?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Security

Major DNS flaw revealed

Experts sound alarms over early disclosure   More...

Nintendo DS

Dodgy Chinese Nintendo chargers recalled

Experience could shock some users   More...

Advertisement

Houses of Parliament

Official 'spying' requests top 500,000

Information includes web records and itemised phone bills   More...

Hacking

Small firms naïve about security

SMBs remain prone to attack, says study   More...

Advertisement