Language Selection

English French German Italian Portuguese Spanish

Security holes haunt RealPlayer

Filed under
Security

Real Networks has fixed four serious security vulnerabilities in its Real, Rhapsody and Helix media players.

Two of the security holes put users at risk of buffer overflow attacks just by playing a media file.

The first vulnerability uses the .avi movie file format to overwrite a compromised PC's heap memory, which in turn allows hackers to take control of a system.

The vulnerability can be triggered by a webpage containing a movie configured to start playing automatically, according to an advisory from eEye, the security consultancy that first reported the vulnerability. It ranks the severity as 'high'.

A hacker could also entice a user to play a movie by promising 'appealing' content.
The flaw affects most RealPlayer software for Windows as well as Rhapsody, which is used for Real's subscription music service.

A similar attack method can be used to exploit another flaw in RealPlayer for OS X, Windows and Linux as well as the Helix Player for Linux.

The method uses a flaw in RealText that is part of the RealMedia file format, which again allows a hacker to take over a system, security experts from iDefense warned in a security advisory.

Full Article.

More in Tux Machines

Firefox OS media-casting stick strikes Kickstarter gold

The first Firefox OS based media player has arrived on Kickstarter, in the form of a $25 open-spec HDMI stick that supports Chromecast-like content casting. The Matchstick, which has already zoomed past its Kickstarter campaign’s $100,000 funding goal, with 28 days still remaining, was teased back in June by Mozilla developer evangelist Christian Heilmann. The unnamed prototype was billed as an open source HDMI stick that runs Mozilla’s Linux-based Firefox OS and offers casting capabilities. Few details were revealed at the time except that the device used the same DIAL (DIscovery And Launch) media-casting protocol created by Netflix and popularized by Google’s Chromecast. Read more

Open source history, present day, and licensing

Looking at open source softwares particularly, this is a fact that is probably useful to you if you are thinking about business models, many people don't care about it anymore. We talk about FOSS, Free and Open Source Software, but if we really are strict there's a difference between free software and open source software. On the left, I have free software which most typically is GPL software. Software where the license insures freedom. It gives freedoms to you as a user, but it also requires that the freedoms are maintained. On the right-hand side, you have open source software which is open for all, but it also allows you to close it. So here we come back to the famous clause of the GPL license, the reciprocity requirement which says, "If I am open, you need to be open." So software that comes under the GPL license carries with it something that other people call a virus. I call it a blessing because I think it's great if all software becomes open. Read more

Leftovers: Software

Proprietary

today's howtos