RealPlayer flaw raises security flags

Powered by SC Magazine
 

Security experts are warning users to be vigilant after the disclosure of a new security vulnerability in RealPlayer..

The flaw could allow an attacker to remotely execute code on a victim's machine.

Security researcher Evgeny Legerov originally posted the vulnerability on New Year's Day, but did not specify the exact nature of the flaw.

Secunia reported in an advisory that the problem is in fact a buffer overflow error. If exploited, the error could cause an application crash which would give an attacker the ability to execute code.

Buffer overflow errors are often used by attackers to install malware. Secunia advises users to avoid opening untrusted files or visiting suspicious websites.

Security firm Sans Institute also urged users to avoid suspicious files and sites, and recommends that system administrators block access to a pair of domains which have shown a history of exploiting RealPlayer flaws.

Copyright ©v3.co.uk


 
 
 
Top Stories
Feeling Shellshocked?
Stay up to date with patching for the Bash bug.
 
Amazon forced to reboot EC2 to patch Xen bug
Rolling restarts over next week.
 
Vodafone reveals plans to store users' online activity
Says retrieval under Govt proposal will impose massive cost.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest Comments
Polls
Which is the most prevalent cyber attack method your organisation faces?




   |   View results
Phishing and social engineering
  66%
 
Advanced persistent threats
  4%
 
Unpatched or unsupported software vulnerabilities
  11%
 
Denial of service attacks
  6%
 
Insider threats
  12%
TOTAL VOTES: 1355

Vote