internet.com
You are in the: Small Business Computing Channelarrow
Small Business Technology
» ECommerce-Guide | Small Business Computing | Webopedia | WinPlanet |Refer-It

WinPlanet Software Downloads and Reviews for Small Businesses
Search
Power Search | Tips
-
Navigate WinPlanet
WinPlanet Home Page

Software
Download Index
In-Depth Reviews
Tips & Tutorials
Updates
News

Software Categories
Browsers
Chat / Conferencing
Desktop Utilities
Development
Internet Apps
Multimedia
OS Service Packs
Productivity Tools

Software Glossary

WinPlanet Newsletter

internet.commerce
Partners & Affiliates













Small Business Computing
Small Business Computing
Ecommerce Guide
Webopedia
WinPlanet

WinPlanet / News

Download of the day
Internet Explorer 8

Most Popular Software Downloads
Opera
Internet Explorer 7
QuickTime for Windows
Winamp
Mozilla Firefox 3
Ad-Aware 2008 Free
Adobe Flash Player
Paint Shop Pro
Adobe Shockwave Player
AVG Anti-Virus Free
7-Zip

Most Popular Software Articles
Windows Vista Tips & Tricks, Part 1
Windows Vista: Worthy of the Hype?
Windows Wireless Zero Configuration: Five Steps to Sanity


Software Reviews

Buffer Overflow Flaw in RealPlayer
Users At Risk of Code Execution Attacks
Ryan Naraine

Digital media delivery firm RealNetworks has patched a potentially serious security flaw in RealPlayer and RealOne, two software products that serve as the hub of the company's streaming media business.

According to an advisory from RealNetworks, the vulnerability could allow an attacker to run arbitrary or malicious code on a user's machine.

The flaw, which is rated "highly critical" by research firm Secunia, affects RealPlayer 10.5 (prior to build 6.0.12.1056), RealPlayer 10, and RealOne Player versions 1 and 2.

RealNetworks said it had received no reports of machines compromised as a result of the vulnerability, which has been patched via the software's built-in update facility. RealPlayer and RealOne users are urged to apply the fix from the "Tools > Check for Update" feature.

The company said the specific buffer overflow exploit was discovered in DUNZIP32.DLL, a module that offers support for ZIP compressed folders in the Windows shell. A successful attacker would have to fashion a malicious skin file to cause a buffer overflow and execute arbitrary code on a customer's machine, RealNetworks said.

eEye Digital Security, which is credited with finding and reporting the flaw to RealNetworks, first discovered the DUNZIP32.DLL vulnerability in August this year. eEye said an exploitable buffer overflow occurs when a user opens a ZIP folder that contains a long file name (greater than around 0x8000 bytes).

Microsoft released a patch for the flaw in its October batch of advisories.

News courtesy of internetnews.com

October 27, 2004


Download RealPlayer Now!Download

Download Windows Media Player Now!Download

View All Media Players

Contents:
1. Users At Risk of Code Execution Attacks




internet.comearthweb.comDevx.commediabistro.comGraphics.com

Search:

Jupitermedia Corporation has two divisions: Jupiterimages and JupiterOnlineMedia

Jupitermedia Corporate Info

Legal Notices, Licensing, Reprints, Permissions, Privacy Policy.
Advertise | Newsletters | Tech Jobs | Shopping | E-mail Offers