RealPlayer flaw raises security flags

Powered by SC Magazine
 

Security experts are warning users to be vigilant after the disclosure of a new security vulnerability in RealPlayer..

The flaw could allow an attacker to remotely execute code on a victim's machine.

Security researcher Evgeny Legerov originally posted the vulnerability on New Year's Day, but did not specify the exact nature of the flaw.

Secunia reported in an advisory that the problem is in fact a buffer overflow error. If exploited, the error could cause an application crash which would give an attacker the ability to execute code.

Buffer overflow errors are often used by attackers to install malware. Secunia advises users to avoid opening untrusted files or visiting suspicious websites.

Security firm Sans Institute also urged users to avoid suspicious files and sites, and recommends that system administrators block access to a pair of domains which have shown a history of exploiting RealPlayer flaws.

Copyright ©v3.co.uk


 
 
 
Top Stories
Toll Group to go Google
Poaches Woolworths project manager.
 
How News Corp's CIO tackled skills in his race to the cloud
What to do when your team’s talents are no longer needed.
 
Photos: How Thodey transformed Telstra
From turbulent Trujillo to Australia's leading telco.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest Comments
Polls
Who do you trust most to protect your private data?







   |   View results
Your bank
  35%
 
Your insurance company
  5%
 
A technology company (Google, Facebook et al)
  9%
 
Your telco, ISP or utility
  8%
 
A retailer (Coles, Woolworths et al)
  4%
 
A Federal Government agency (ATO, Centrelink etc)
  18%
 
An Australian law enforcement agency (AFP, ASIO et al)
  15%
 
A State Government agency (Health dept, etc)
  7%
TOTAL VOTES: 3966

Vote
Do you support the abolition of the Office of the Information Commissioner?

   |   View results
I support shutting down the OAIC.
  27%
 
I DON'T support shutting the OAIC.
  73%
TOTAL VOTES: 1353

Vote