Latest Comments
"I feel it with you guys. These irritating interruptions on privacy MUST be stopped. It is a ..."
by Jan Wilmans | Dec 2, 2008 7:11 PM
 
"My AVG WILL NOT UPDATE"
by James Downs | Dec 2, 2008 5:58 AM
 
"Concerned man's comments seem to intimate that if I'm using agents all will be well but the ..."
by Werner K | Nov 26, 2008 8:36 PM
 
"That will enhance Microsoft Office system, including SharePoint - good platform for enterprise ..."
by SGE | Nov 25, 2008 3:29 PM
 
"how many users allow per session? because the digital persona password manager allows only 10 ..."
by Daniel | Nov 25, 2008 12:14 AM

In-the-wild attacks target RealPlayer zero-day flaw

  • Email a Friend
  • Print Page
By Staff Writers
Oct 22, 2007 11:21 AM
Tags: In-the-wild | attacks | target | RealPlayer | zero-day | flaw
Javier Santoyo, senior manager of emerging technologies at Symantec Security Response, said the attacks appear limited in scope, but users nonetheless should take precautions.

"It hits RealPlayer, and RealPlayer is popular," he told SCMagazineUS.com today. "And also it's unpatched."

When a user installs RealPlayer, the program installs a browser-helper object and an ActiveX control, which provide additional functionality when using the application in Internet Explorer. But the ActiveX control is flawed and permits attackers to pass long parameters and cause stack-based overflows, Santoyo said.

That results in the ability to execute arbitrary code and infect a victim's machine with a trojan downloader, he said.

Users can become infected when they are lured to malicious rogue websites, likely those that contain third-party advertisements containing malicious JavaScript, Santoyo said.

RealNetworks spokesman Bill Hankes told SCMagazineUS.com today that engineers are working on a patch "as we speak" and the company planned to provide a fix timeline today.

The vulnerability affects the most recent RealPlayer versions, 10.5 and 11, he said. The company has received no reports of compromised end-user PCs.

"We take any security vulnerability very seriously," Hankes said.

Santoyo said that in lieu of a patch, businesses can use any of several options to alleviate the threat. They can block the IP addresses used to perpetrate the attack, disable the browser prompt that permits active scripting to execute and set the kill-bit for the affected ActiveX control.

See original article on SC Magazine US

Secure Computing Magazine

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Tripwire - Click here to win an iTouch
 
 
Vulnerabilities & Exploits Whitepapers