Language Selection

English French German Italian Portuguese Spanish

Security holes haunt RealPlayer

Filed under
Security

Real Networks has fixed four serious security vulnerabilities in its Real, Rhapsody and Helix media players.

Two of the security holes put users at risk of buffer overflow attacks just by playing a media file.

The first vulnerability uses the .avi movie file format to overwrite a compromised PC's heap memory, which in turn allows hackers to take control of a system.

The vulnerability can be triggered by a webpage containing a movie configured to start playing automatically, according to an advisory from eEye, the security consultancy that first reported the vulnerability. It ranks the severity as 'high'.

A hacker could also entice a user to play a movie by promising 'appealing' content.
The flaw affects most RealPlayer software for Windows as well as Rhapsody, which is used for Real's subscription music service.

A similar attack method can be used to exploit another flaw in RealPlayer for OS X, Windows and Linux as well as the Helix Player for Linux.

The method uses a flaw in RealText that is part of the RealMedia file format, which again allows a hacker to take over a system, security experts from iDefense warned in a security advisory.

Full Article.

More in Tux Machines

Alice is killing the trolls -- but expect patent lawyers to strike back

Open source software developers rejoice: Alice Corp. v CLS Bank is fast becoming a landmark decision for patent cases in the United States. The Court of Appeals for the Federal Circuit, which handles all appeals for patent cases in the United States, has often been criticized for its handling of these cases -- Techdirt describes it as "the rogue patent court, captured by the patent bar." But following the Alice decision, the Court of Appeals seems to have changed. Read more

How to Give your Smartphone the Android L Look

Android L is Google's latest mobile operating system. Apart from a complete UI overhaul, this version brings along a myriad of performance improvements. Compared to its competitor iOS 8, Android L outperforms the Apple mobile operating system in design and performance. Though there is no clear announcement as to when Android L will be reaching our devices, its Material Design has slowly started catching up among app developers. Furthermore, many apps have come up that let you completely change the Android smartphone’s user interface to match that of Android L. Although many of those apps are annoyingly hard to use, some of them make the job really simple. Below, we'll show you how to make the most out of such apps and then transform your phone’s UI to completely match the Android L look. Read more

Webconverger 26 Is a Secure Kiosk OS That Doesn't Store Any Data

Webconverger is a distribution designed and developed with a single goal in mind, namely to provide the best Kiosk experience possible. This means that people will be able to use that OS as a regular system, although its functionality will be limited and it will be impossible to install any other apps. This is a very helpful solution if this is a public PC, like in a library or a cafe, and it preserves the quality of the installation for a very long time. Because users can't interact with it on a deeper level, the operating system will remain stable and it will be pretty much the same like in the first day that it was used. Read more

Today in Techrights