What the Tech logo
Welcome! Register for a free account (or login) > How does it work?
  1. Quickly register. It will only take 60 seconds.
  2. Start a new topic. Ask your question. Wait for an email reply.
  3. Is your system infected? Begin reading the malware removal guide.
register button
Reply to this topicStart new topic
> RealPlayer vuln - update available
AplusWebMaster
post Apr 3 2008, 03:29 AM
Post #1


AplusWebMaster
*****

Group: Authentic Member
Posts: 4,575
Joined: 30-December 03
From: USA
Member No.: 1,643
Operating System: XP/SP3



(RealPlayer is installed on almost -all- Windows PC's, since it comes installed with a new PC.)

RealPlayer ActiveX vuln
- http://secunia.com/advisories/29315/
Last Update: 2008-03-24
Critical: Highly critical
...The vulnerability is confirmed in RealPlayer version 11.0.1 (build 6.0.14.794) including rmoc3260.dll version 6.0.10.45. Other versions may also be affected...

>>> Solution: Update to version 11.0.2 (build 6.0.14.802) via e.g. "Check for Update" in the "Help->About RealPlayer" menu...

(Still, no update announcement here:
- http://service.real.com/realplayer/security/en/
Last entry - October 25, 2007)

RealPlayer exploit in the wild: http://isc.sans.org/diary.html?storyid=3810
Last Updated: 2008-01-05 20:13:55 UTC

ph34r.gif ph34r.gif
Go to the top of the page
 
+Quote Post
 
Start new topic
Replies (1 - 1)
AplusWebMaster
post Apr 4 2008, 05:39 AM
Post #2


AplusWebMaster
*****

Group: Authentic Member
Posts: 4,575
Joined: 30-December 03
From: USA
Member No.: 1,643
Operating System: XP/SP3



FYI...

RealPlayer Vulnerability Being Exploited in the Wild
- http://preview.tinyurl.com/2trstc
April 3, 2008 (Symantec Security Response Weblog) - "...Update: It appears that this vulnerability has been patched within RealPlayer version 11.0.2 (build 6.0.14.802), which is now available for download. It contains version 6.0.10.50 of the rmoc3260.dll file, which we have determined no longer contains the vulnerability. Current RealPlayer users can use the Check for Update utility, which will also install a version of the .dll file that is no longer vulnerable to this exploit."

- http://secunia.com/advisories/29315/
"...Solution: Update to version 11.0.2 (build 6.0.14.802) via e.g. "Check for Update" in the "Help->About RealPlayer" menu..."

'Still no advisory posted about the release here:
- http://service.real.com/realplayer/security/en/
(Last updated) - October 25, 2007 RealPlayer Update

ph34r.gif
Go to the top of the page
 
+Quote Post

Reply to this topicStart new topic

 


RSS Time is now: 21st March 2010 - 01:39 PM
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk.
Member site: Alliance of Security Analysis Professionals | UNITE Against Malware
Memory Forums | Auto Repair Forum
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy