'Highly critical' RealPlayer flaw patched up

Buffer overflow faults letting in those pesky hackers

By John Borland, 22 April 2005 09:35

NEWS RealNetworks has released a security patch aimed at plugging a flaw in its multimedia software that could allow hackers to run their own code on people's computers.

The flaw, rated a "highly critical" risk by security company Secunia, affects most recent consumer versions of the RealPlayer media player software, for both Windows and Macintosh operating systems. Also at risk are some, but not the most recent, versions of the software for Linux. The flaw exists in some RealOne Player versions too, RealNetworks said.

The company released the patch for the flaw on Tuesday.

"RealNetworks has received no reports of machines compromised as a result of the now-remedied vulnerabilities," the company said on its website. "RealNetworks takes all security vulnerabilities very seriously."

So-called buffer overflow faults, which can be exploited by a hacker to swamp a program with unexpected information and use the resulting data spillover to run malicious code, have become a common discovery in many of the most popular software programs.

The Mozilla Foundation's Firefox web browser, Apple Computer's iSync program and numerous kinds of Microsoft software have all been found to carry similar risks and have been patched over time.

John Borland writes for CNET News.com.

Post your comment

In order to post a comment you need to be registered and logged in.

Log in or create your silicon.com account below

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy.

Questions about membership? Find the answers in the Membership FAQ