RealNetworks,
Inc. Releases Update to Address Security Vulnerabilities.
Updated
May 15, 2012
RealNetworks is making available product
upgrades that contain security bug fixes. We have received no reports of any machines
actually being compromised as a result of the now-remedied vulnerabilities.
RealNetworks always recommends upgrading your
product to the most current version available to avoid security
vulnerabilities.
Current Software
The current versions of
our Player software are not affected by these vulnerabilities.
|
Software |
Affected? |
Operating System |
Language |
|
RealPlayer
15.0.4.53 |
No |
Windows
XP, Vista, Win7 |
All
Supported |
|
Mac
RealPlayer 12.0.0.1725 |
No |
Mac
OS X 10.3 – 10.6 |
All
Supported |
Affected Software
The
table below contains a summary of which previous and current versions of the
RealPlayer software are susceptible to these vulnerabilities. The columns and
cells in green are the versions of each product where the issue has been
resolved.
|
CVE Number |
RealPlayer |
RealPlayer SP 1.0 –
1.1.5 |
RealPlayer 14.0.0 –
15.0.3.37 |
RealPlayer 15.0.4.53 |
|
Mac RealPlayer 12.0.0.1701 |
Mac RealPlayer 12.0.0.1725 |
|
CVE-2012-1904 |
X |
X |
X |
|
|||
|
CVE-2012-2406 |
X |
X |
X |
|
|||
|
CVE-2012-2411 |
X |
X |
X |
|
CVE Descriptions
CVE-2012-1904
RealPlayer
- MP4 file handling memory corruption
Affected software: Windows RealPlayer 15.0.3.37 and
prior.
Credit to Craig Young of nCircle for reporting this issue.
CVE-2012-2406
RealPlayer
- RealMedia ASMRuleBook
parsing can allow remote code execution
Affected software: Windows RealPlayer 15.0.3.37 and
prior.
Credit to Tom Gallagher working with the Beyond Security's SecuriTeam Secure Disclosure for reporting this issue.
CVE-2012-2411
RealPlayer
- RealJukebox Media parser buffer overrun
Affected software: Windows RealPlayer 15.0.3.37 and prior.
Credit to Sebastian
Apelt for reporting this issue.
Warranty:
RealNetworks
Inc. endeavors to provide you with the highest quality products and services,
but cannot guarantee, and does not warrant, that the operation of any
RealNetworks product will be error-free, uninterrupted or secure. Please see
your original license agreement for details of our limited warranty or warranty
disclaimer.