AplusWebMaster
Topic Starter
FYI…
- http://service.real.com/help/faq/security/050623_player/EN/
"RealNetworks, Inc. Releases Update to Address Security Vulnerabilities.
Updated June 23, 2005
RealNetworks, Inc. has addressed recently discovered security vulnerabilities that offered the potential for an attacker to run arbitrary or malicious code on a customer's machine. RealNetworks has received no reports of machines compromised as a result of the now-remedied vulnerabilities. RealNetworks takes all security vulnerabilities very seriously.
The specific exploits were:
Exploit 1: To fashion a malicious MP3 file to allow the overwriting of a local file or execution of an ActiveX control on a customer's machine.
Exploit 2: To fashion a malicious RealMedia file which uses RealText to cause a heap overflow to allow an attacker to execute arbitrary code on a customer's machine.
Exploit 3: To fashion a malicious AVI file to cause a buffer overflow to allow an attacker to execute arbitrary code on a customer's machine.
Exploit 4: Using default settings of earlier Internet Explorer browsers, a malicious website could cause a local HTML file to be created and then trigger an RM file to play which would then reference this local HTML file.
Workaround
To ensure that your Player is protected, we recommend installing the available updates."
>>> Windows users can apply the updates via the "Tools > Check for Updates" feature of the software.

- http://service.real.com/help/faq/security/050623_player/EN/
"RealNetworks, Inc. Releases Update to Address Security Vulnerabilities.
Updated June 23, 2005
RealNetworks, Inc. has addressed recently discovered security vulnerabilities that offered the potential for an attacker to run arbitrary or malicious code on a customer's machine. RealNetworks has received no reports of machines compromised as a result of the now-remedied vulnerabilities. RealNetworks takes all security vulnerabilities very seriously.
The specific exploits were:
Exploit 1: To fashion a malicious MP3 file to allow the overwriting of a local file or execution of an ActiveX control on a customer's machine.
Exploit 2: To fashion a malicious RealMedia file which uses RealText to cause a heap overflow to allow an attacker to execute arbitrary code on a customer's machine.
Exploit 3: To fashion a malicious AVI file to cause a buffer overflow to allow an attacker to execute arbitrary code on a customer's machine.
Exploit 4: Using default settings of earlier Internet Explorer browsers, a malicious website could cause a local HTML file to be created and then trigger an RM file to play which would then reference this local HTML file.
Workaround
To ensure that your Player is protected, we recommend installing the available updates."
>>> Windows users can apply the updates via the "Tools > Check for Updates" feature of the software.