03 Apr 2003
Security warnings have been released for two of the most popular digital media players - RealNetworks' RealOne player and Apple's QuickTime.
RealNetworks released an advisory warning that its flagship RealOne Player is at risk both on Windows and Mac OS X, as well as RealOne Player version 2 for Windows, RealPlayer 8 for Windows and Mac OS 9, RealOne Enterprise Desktop Manager and RealOne Enterprise Desktop.
The company warned that a maliciously corrupted Portable Network Graphicfile, viewable through a web browser, could cause 'heap corruption' and allow an attacker to execute arbitrary code on a system.
Experts are also warning of an unrelated vulnerability in Apple's QuickTime media player, where an exploitable buffer overflow could allow for the execution of arbitrary code.
Security firm iDefense released an advisory detailing how a URL containing more than 400 characters would overrun allocated space on the stack and allow arbitrary code to be slotted in.
"Any remote attacker can compromise a target system if he or she can convince a user to load a specially crafted exploit URL," the company said.
"Upon successful exploitation, arbitrary code can be executed under the privileges of the user who launched QuickTime."
QuickTime Player versions 5.x and 6.0 for Windows are vulnerable, but QuickTime for Mac OS is not. Apple has since released QuickTime 6.1, which patches the flaws on Windows.
Latest stories from Security
Related articles
Related jobs
Poll
Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?
Orange and Intel talk us through the ins and outs of their San Diego smartphone
Connect with V3.co.uk
Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them
The importance of understanding your infrastructure
Python Developer / Python Django Team Leader London 55k...
Java Architect / Application Architect London 70k...
SQL Server Developer SQL Server Banking SQL Server...
User Interface Developer / UI Developer / User interface...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?