Version: 2008
  • On MovieTome: Why you didn't see Shatner in TREK

October 1, 2004 4:25 PM PDT

Viral movies possible with RealPlayer flaw

  • 4 comments
A software slipup in RealNetworks' music player means that Windows, Mac and Linux computers could be compromised by a fake movie file, a security company said Friday.

The problem means that fake movie files could be created that, when played by vulnerable Real software, would run a program instead. The flaw appears in RealPlayer 10 for Windows and Mac OS X, the RealOne Player for Windows and Mac OS X and the Real Helix Player for Linux.

"Anyone who has RealPlayer is affected, and there are many people with RealPlayer," said Marc Maiffret, chief hacking officer at software security company eEye Digital Security, the company that discovered the security issue.

RealNetworks could not immediately be reached for comment.

RealNetworks has issued patches for the flaw.

The flaw occurs in a component of Real's software that handles Real movie files with the .rm extension, according to eEye's advisory.

Similar to the recent flaw in Windows applications that handle the JPEG image format, this vulnerability affects a widespread piece of software and could be used to create a virus.

"It's similar to the JPEG flaw in the sense that just by viewing the file, or having the file 'force viewed' through a Web browser, your system can be compromised," Maiffret said. "I think both this JPEG vulnerability and the RealPlayer vulnerability are good examples of a type of threat that is becoming more prevalent: client-side vulnerabilities."

Rather than finding a security hole in the operating system and gaining direct access to a computer, attackers are now increasingly looking at exploiting widely used applications.

"Most security software...is not able to defend itself well against these client-based vulnerabilities, leaving companies with few alternatives other than patching," Maiffret said.

Add a Comment (Log in or register) (4 Comments)
  • prev
  • 1
  • next
Where are the comments?
by October 3, 2004 6:18 AM PDT
I'm completely surprised by the lack of comments on this article.

Where are the usual software bashers when a serious flaw is found in a product from a company other than Microsoft? And this affects Linux too! Can you believe it?! You'd think by some of the comments people make bashing MS and the software they create along with the encouragement to drop Windows and move to Linux that Linux didn't have any vulnerabilities at all. Of course, I find that most of the people making comments like that have no idea what they?re talking about to begin with.

If this had been a MS only issue the threads would have been flying in this forum.
Reply to this comment
I would reply....
by Earl Benser October 3, 2004 9:53 AM PDT
... but I trashed Real Player some time ago. It's hard to complain
about long gone software.

And as far as the company goes, while I do believe that it's staff
is generally less than technically competent, apparently the
company meets the same set of criteria people use to justify
M$'s existance. Well, maybe the net assets category is somewhat
lacking......
View reply
Well
by simcity1976 October 3, 2004 1:26 PM PDT
MS did it again, oh wait
no they didn't my bad...
(4 Comments)
  • prev
  • 1
  • next
advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

Markets

Market news, charts, SEC filings, and more

Related quotes

RealNetworks (3.36%) 0.11 3.38
Microsoft (2.04%) 0.60 30.01
Dow Jones Industrials (1.23%) 126.74 10,471.58
S&P 500 (1.21%) 13.23 1,108.86
NASDAQ (1.46%) 31.21 2,175.81
CNET TECH (1.30%) 20.52 1,595.41
  Symbol Lookup
advertisement

Inside CNET News

Scroll Left Scroll Right