Navigation & Login
Go Back   TechCountry > Software > Security
Security Anti virus, Firewalls, Exploits and other security concerns
Home      Site Rules     Downloads      Affiliates      How-To Tutorials     
Reply

Old 03-11-2008, 06:07 PM
Administrator
 
Kevin's Avatar
 
Join Date: Feb 2008
Location: LA Cali
Posts: 1,405
Thanks: 1
Thanked 4 Times in 4 Posts
Rep Power: 30 Kevin is on a distinguished road
Send a message via MSN to Kevin
Exclamation RealPlayer problem

RealPlayer vulnerable in Internet Explorer

Quote:
Posted by Robert Vamosi | 5 comments


If you use the RealPlayer on Internet Explorer, watch out. Researcher Elazar Broad has posted to the Full Disclosure mailing list a so-called heap overflow vulnerability that makes it possible for an attacker to modify heap blocks after they are freed and overwrite certain registers. This could allow code execution on a compromised machine. The vulnerability affects all versions of RealPlayer running under Internet Explorer.
Exploit code for this flaw has not yet been made public.
Without a patch from RealPlayer, security experts recommend disabling the killbit for the following ActiveX ClassIDs:
  • 2F542A2E-EDC9-4BF7-8CB1-87C9919F7F93
  • CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA
Please note that disabling the killbits above will also remove some functionality within the player.
To avoid the loss of functionality, security experts recommend using RealPlayer in a browser that doesn't support ActiveX, such as Mozilla Firefox (for Windows and Mac).


Originally posted at Defense in Depth.
__________________
-Webmaster aka Kevin-J
Kevin is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


vBulletin Style by: vbdesigns.de

All times are GMT -5. The time now is 09:44 AM.
Powered by vBulletin® Version 3.7.0 Beta 4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.1.0 ©2007, Crawlability, Inc.
TechCountry - 2008