Home > Security News > Exploit code targets RealPlayer, researchers warn
Security News:
EMAIL THIS LICENSING & REPRINTS

Exploit code targets RealPlayer, researchers warn

By SearchSecurity.com Staff
02 Jan 2008 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

The United States Computer Emergency Readiness Team (US-CERT) is warning of working exploit code targeting a zero-day flaw in the latest version of RealPlayer.

The flaw affects RealPlayer 11 build 6.0.14.748.

Evgeny Legerov, founder of Russian-based security firm, Gleg, announced a few details of the code. Legerov posted a brief announcement at the Dailydave security discussion board. In his post, Gleg links to a flash demonstration of the working code.

Gleg released the exploit code Dec. 16 to customers that license its periodic updates via its VulnDisco Step Ahead exploit packages. The packages are used with Immunity CANVAS testing software.

Seattle-based Real said it is working to determine the validity of the exploit code.

In October, Real released a patch for 10.5 and 11 beta to remove a security flaw attackers had actively targeted.

Media players are a constant target of attackers.

In late November, exploit code surfaced for a zero-day buffer-overflow flaw in Apple Inc.'s widely used QuickTime media player, giving attackers the opportunity to hijack vulnerable computers running Mac OS X and the latest versions of Microsoft Windows.

Also a serious glitch was discovered in November in how applications from a variety of vendors process audio FLAC files, opening the door for attackers to hijack vulnerable computer systems.



Sound Off! -   Be the first to post a message to Sound Off!


Tags: Emerging Information Security ThreatsSecuring Productivity ApplicationsVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineWebcastsWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts