RealNetworks to review security for RealOne Player

Real Networks have announced that they are undertaking a "...comprehensive security review to address buffer overrun exploit vulnerabilities in RealOne Player". This comes after weeks of frustration for Real, who have failed miserably in plugging up the holes in the insecure player.

The security flaws were first made public on the 21st of November, and a fix is still not available.

Mark Litchfield, a security hotshot with UK-based application security company NGS software, found the original vulnerabilities, and provided Real with information on how to fix them.

Real posted a fix on the 21st of November, but Litchfield quickly found that the patch didn't completely work and Real were forced to take the patch offline.

To add insult to injury, Litchfield found another set of serious vulnerabilities in the product at around the same time.

Users of the Real products are still waiting for a patch that works.

"I will say though that Real have been very quick in fixing any new issues that I have discovered, it was just unfortunate that their original patch did not do it's required job," Litchfield told ZDNet Australia.

"Chances are had they fixed them, I probably would not have revisited RealOne to look for more vulnerabilities," he added.

Real say that they "...are working with industry security professionals to verify and fix recently identified 'buffer overrun' errors in the RealOne Player".

Real are hoping that their comprehensive review of the RealOne Player code will reduce the probability of more security holes being discovered in the product in the future.

Litchfield has not been critical of the way in which Real have handled the security drama. "...in regards to fixing security issues they still come out extremely well," he said.

Real hope to release a comprehensive patch for the affected products on December 25. There are over 250 million registered users of Real Network's software.

Advertisement

Talkback 0 comments

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Jacquelyn Holt G'Day USA: Aussie start-ups head to America
    The G'Day USA: Australia Week campaign today announced the finalists for the Innovation Shoot Out event, which will see eight Australian technology start-ups travel to San Francisco in January 2010 to demonstrate the commercial viability of their products in the US.
  • Array All I want for Xmas is Telstra pricing
    Five consecutive days without broadband has led me to what seemed at the time to be an act of desperation: contemplating signing up for Telstra's 100Mbps cable modem service.
  • Array Sick of broken tender sites
    Some of the state governments desperately need to invest in more user-friendly tender sites so that looking for information on government tenders doesn't have to be a game of blind man's bluff.
  • More blogs »

Tags

Back to top

Featured