|
|
| |
| RealNetworks has reported a vulnerability in RealOne Player, which can be exploited by malicious people to execute arbitrary code. |
| |
Credit:
The information has been provided by KrazySnake, DigitalPranksters.
|
| |
Vulnerable systems:
* RealOne Player (English only)
* RealOne Player v2 for Windows (all language versions)
* RealOne Enterprise Desktop (all versions, standalone and as configured by the RealOne Desktop Manager)
The vulnerability is caused due to an error in the handling of SMIL files. This can be exploited to execute script code in the context of an arbitrary domain or the local system by constructing a specially crafted SMIL file and tricking a user into executing it.
Solution:
Updates for RealOne Player can be installed by using the "Check for Update" feature.
Update RealOne Desktop Manager: http://licensekey.realnetworks.com/rnforms/products/tools/rdm/index.html.
Update RealOne Enterprise Desktop: http://forms.real.com/rnforms/products/tools/red/index.html.
|
|
|
|
|
|
|
|