All the latest UK technology news, reviews and analysis

Glitches found in RealOne and QuickTime

by James Middleton

03 Apr 2003

Be the first to comment

  • Tweet this

Security warnings have been released for two of the most popular digital media players - RealNetworks' RealOne player and Apple's QuickTime.

RealNetworks released an advisory warning that its flagship RealOne Player is at risk both on Windows and Mac OS X, as well as RealOne Player version 2 for Windows, RealPlayer 8 for Windows and Mac OS 9, RealOne Enterprise Desktop Manager and RealOne Enterprise Desktop.

The company warned that a maliciously corrupted Portable Network Graphicfile, viewable through a web browser, could cause 'heap corruption' and allow an attacker to execute arbitrary code on a system.

Experts are also warning of an unrelated vulnerability in Apple's QuickTime media player, where an exploitable buffer overflow could allow for the execution of arbitrary code.

Security firm iDefense released an advisory detailing how a URL containing more than 400 characters would overrun allocated space on the stack and allow arbitrary code to be slotted in.

"Any remote attacker can compromise a target system if he or she can convince a user to load a specially crafted exploit URL," the company said.

"Upon successful exploitation, arbitrary code can be executed under the privileges of the user who launched QuickTime."

QuickTime Player versions 5.x and 6.0 for Windows are vulnerable, but QuickTime for Mac OS is not. Apple has since released QuickTime 6.1, which patches the flaws on Windows.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

33%

1%

11%

55%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Python Django Developer 55k

Python Developer / Python Django Team Leader London 55k...

Application Architect - Java London

Java Architect / Application Architect London 70k...

SQL Server Developer 60k

SQL Server Developer SQL Server Banking SQL Server...

User Interface Developer Cloud London Finance

User Interface Developer / UI Developer / User interface...

To send to more than one email address, simply separate each address with a comma.