Friday, March 24, 2006

RealNetworks has published updates to fix several vulnerabilities found in its multimedia players.

Even though they claim not to have received any actual reports of incidents related to these security flaws yet, we recommend all affected users apply these patches.

The first one of the flaws solved could allow a local user to extend their privileges, whereas the three others are related to buffer overruns in players when processing different types of files.

We recommend users of RealPlayer, RealOnePlayer, Rhapsody and Helix Player to check availability of updates, with the exception of users of versions for Nokia Series60 and Palm, which are not vulnerable.

The whole list of vulnerable products and download and installation instructions (for Windows, Mac and Linux) are detailed in the RealNetworks official notification, at http://www.service.real.com/realplayer/security/03162006_player/en/