RealNetworks, Inc. Releases Update to Address Security Vulnerabilities.
Updated August 14, 2008
RealNetworks
is making available product upgrades that contain security bug fixes.
RealNetworks is updating the RealPlayer 11 build
(11.0.3) announced on July 25th to include components for localized versions of
the release that were not included in the original update. The new build,
known as RealPlayer 11.0.3a, should be installed for any non-U.S. English
versions of RealPlayer 11.
RealPlayer 11.0.3 of the U.S. language version
did address all security bug fixes as intended from the July 25th
post.
RealNetworks
recommends that if you have installed a product version listed in the table
below, you upgrade your product to the current version of the product.
Affected
Software: (Please see below for details of potential
vulnerabilities).
|
Windows
|
Instructions
If you are on Windows XP or
If you
are on Windows 2000, Windows ME or Windows 98SE, you may get the security
updates in the most recent version of RealPlayer 10.5 by following the
instructions below.
RealOne
Player (English only), RealOne Player V2, RealPlayer 10 and RealPlayer 10.5
customers require a full download to correct this issue. Please use the
following steps to upgrade your Player:
1.
In the
Tools menu select Check for Update.
2.
Select
the box next to the "RealPlayer 10.5 with Harmony™ Technology" component.
Click
Install to download and install the update
RealPlayer
8 (version 6.0.9.584) customers please use the following steps to upgrade your
Player:
1.
Go the
Help menu.
2.
Select
Check for Update.
3.
Select
the box next to the "RealPlayer 10.5 with Harmony™ Technology" component.
4.
Click
Install to download and install the update.
RealPlayer
10 for Mac OS X customers need to get the latest player to address this security
issue. Please click here to upgrade your RealPlayer 11.
Please
click here to
get an updated RealPlayer 11 for Linux.
Details
for Potential Vulnerabilities:
- Vulnerability
1:
The
identified vulnerability is a RealPlayer ActiveX controls property heap memory
corruption. CVE-2008-1309
- Vulnerability
2:
The
identified vulnerability is a Local resource reference vulnerability in
RealPlayer. CVE-2008-3064
- Vulnerability
3:
The
identified vulnerability is a RealPlayer SWF file heap-based buffer overflow.
CVE-2007-5400
- Vulnerability
4:
The
identified vulnerability is a RealPlayer ActiveX import method buffer overflow.
CVE-2008-3066
Acknowledgements:
RealNetworks
would like to acknowledge Dyon Balding,
Elazar Broad, CERT/CC, Haifei Li
and Peter Vreugdenhil working with TippingPoint for bringing
these exploits to our attention as well as those who subsequently worked with
RealNetworks to correct the vulnerabilities.
Warranty:
RealNetworks
Inc. endeavors to provide you with the highest quality products and services,
but cannot guarantee, and does not warrant, that the operation of any
RealNetworks product will be error-free, uninterrupted or secure. Please see
your original license agreement for details of our limited warranty or warranty
disclaimer.