Computer ForumsComputers  

Go Back   Computer Forums > The World Wide Web > Virus - Spyware Protection / Detection

Reply
 
LinkBack Thread Tools Display Modes
Old 03-13-2008, 09:43 AM   #1 (permalink)
Security/Hacking Mod
 
Osiris's Avatar
 
Join Date: Jan 2005
Location: USA
Posts: 24,120
Default Real Player Internet Explorer vulnerability

Internet Explorer with an installed version of Real Player beware. A vulnerability has been discovered recently which could allow remote code execution. According to Zdnet users should either switch browsers for the time until an patch is released or disabling killbits for two Active X classes. They forgot to mention the third option which would be to uninstall Real Player (temporarily).
Affected are all Real Player versions running under Internet Explorer. Microsoft has an article up that explains Killbits and what they do. They basically prevent Active X controls from being loaded in Internet Explorer. I still would recommend to either switch to Firefox or Opera temporarily or uninstall Real Player for the time until a security patch has been created.
Researcher Elazar Broad has posted to the Full Disclosure mailing list a so-called heap overflow vulnerability that makes it possible for an attacker to modify heap blocks after they are freed and overwrite certain registers.
The killbits that should be disabled are the following:
  • 2F542A2E-EDC9-4BF7-8CB1-87C9919F7F93
  • CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA
This will definitely have the effect that some Real Player functions will stop working properly.

Real Player Internet Explorer vulnerability
Osiris is offline   Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Crysis 1.2 patch dario03 PC Gaming 34 08-29-2008 01:42 AM
Help With Windows Explorer And Windows Internet Explorer 7! EskimoGenius Windows Operating Systems and Software 0 07-26-2007 03:54 AM
The end of net neutrality = bad kfc469 Off Topic Discussion 18 07-10-2007 11:02 AM
My Internet Explorer Schmidt1989 Windows Operating Systems and Software 1 06-25-2007 09:39 PM
internet explorer HElp MAAX Z Browser & General Internet Questions 0 04-24-2007 06:52 PM


All times are GMT -5. The time now is 03:35 AM.


Powered by vBulletin® Version 3.7.1
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.1.0