main
Report a problem

RealPlayer flaw: Stop using Internet Explorer

Steven Parker   on 13 March 2008 - 10:56 · 34 comments & 25745 views

Advertisement (Why?)
Security experts are warning RealPlayer users to stop using Internet Explorer until a patch is released for a flaw researchers discovered which could allow code execution. Researcher Elazar Broad has posted to the Full Disclosure mailing list a so-called heap overflow vulnerability that makes it possible for an attacker to modify heap blocks after they are freed and overwrite certain registers.

This could allow code execution on a compromised machine. The vulnerability affects all versions of RealPlayer running under Internet Explorer. Exploit code for this flaw has not yet been made public.

Without a patch from RealPlayer, security experts recommend disabling the killbit for the following ActiveX ClassIDs:
  1. 2F542A2E-EDC9-4BF7-8CB1-87C9919F7F93
  2. CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA

However, disabling these killbits will also remove some functionality within the player.

To avoid the loss of functionality, security experts recommend using RealPlayer in a browser that doesn't support ActiveX, such as Mozilla Firefox (for Windows and Mac).

News Source: ZDNet Australia

Post a comment · Send to friend Comments · There are 34 additional comments
#1 +sLm4ever on 13 Mar 2008 - 10:57
just stop using both RealPlayer and IE =\ ...
(3 replies) #2 vetneufuse on 13 Mar 2008 - 11:07
How about we stop using realplayer?
#2.1 guruparan on 13 Mar 2008 - 11:37
(neufuse said @ #2)
How about we stop using realplayer?


+1
#2.2 MightyJordan on 13 Mar 2008 - 13:01
(guruparan said @ #2.1)
(neufuse said @ #2)
How about we stop using realplayer?


+1

+2. The only reason I've got it installed is because some people still use their formats online, and Real/Quicktime Alternative won't work online, so I've got Quicktime installed as well.

Speaking of formats, I was left puzzled earlier this week wondering why almost everyone uses .avi over .wmv. I converted some videos from .avi to .wmv using Any Video Converter, kept it at the same resolution and quality. In .avi, the files totaled 2.64GB, but in .wmv, I saved over 1GB! It was exactly the same as well, playback wise.
#2.3 vetneufuse on 13 Mar 2008 - 14:26
(MightyJordan said @ #2.2)
(guruparan said @ #2.1)
(neufuse said @ #2)
How about we stop using realplayer?


+1

+2. The only reason I've got it installed is because some people still use their formats online, and Real/Quicktime Alternative won't work online, so I've got Quicktime installed as well.

Speaking of formats, I was left puzzled earlier this week wondering why almost everyone uses .avi over .wmv. I converted some videos from .avi to .wmv using Any Video Converter, kept it at the same resolution and quality. In .avi, the files totaled 2.64GB, but in .wmv, I saved over 1GB! It was exactly the same as well, playback wise.


Because Divx and xvid is a major format... which is cross platform... WMV is semi cross platform... mainly apple and windows... divx is supported by dvd players too generally
#3 rdmiller on 13 Mar 2008 - 11:23
Uninstall RealPlayer.
(1 reply) #4 rpgfan on 13 Mar 2008 - 11:30
Is there any alternative to RealPlayer? Even Real Alternative and VLC don't do the job sometimes... I've given up on the RealPlayer formats. On my machine, the browser plugins take even longer to load than Java (for that, I thank Sun).

As for RealPlayer itself, who in the world still uses it? I haven't seen it in my town for quite some time.
#4.1 GreyWolfSC on 13 Mar 2008 - 13:40
(rpgfan said @ #4)
Is there any alternative to RealPlayer? Even Real Alternative and VLC don't do the job sometimes... I've given up on the RealPlayer formats. On my machine, the browser plugins take even longer to load than Java (for that, I thank Sun).

As for RealPlayer itself, who in the world still uses it? I haven't seen it in my town for quite some time.


You can send an e-mail to the content provider and tell them you won't use it 'til it's in a better format, but it probably wouldn't help.
(4 replies) #5 Ficman on 13 Mar 2008 - 11:38
Good Lord.... Who uses Realplayer anymore... If you haven't yet, stop using it...
#5.1 Davebo on 13 Mar 2008 - 14:24
(Ficman said @ #5)
Good Lord.... Who uses Realplayer anymore... If you haven't yet, stop using it...


Of course, the following is true as well....

"Good Lord.... Who uses Internet Explorer anymore... If you haven't yet, stop using it..."
#5.2 vetneufuse on 13 Mar 2008 - 14:35
(Davebo said @ #5.1)
(Ficman said @ #5)
Good Lord.... Who uses Realplayer anymore... If you haven't yet, stop using it...


Of course, the following is true as well....

"Good Lord.... Who uses Internet Explorer anymore... If you haven't yet, stop using it..."


can't say that when the majority of the market uses it I'd say over 85% of the world using it is a majority...
#5.3 Ficman on 13 Mar 2008 - 14:47
(neufuse said @ #5.2)
(Davebo said @ #5.1)
(Ficman said @ #5)
Good Lord.... Who uses Realplayer anymore... If you haven't yet, stop using it...


Of course, the following is true as well....

"Good Lord.... Who uses Internet Explorer anymore... If you haven't yet, stop using it..."


can't say that when the majority of the market uses it I'd say over 85% of the world using it is a majority...



I'd love to know where that % comes from, nobody I know allows it on any of the networks they manage nor do we allow it.

Source please?

#5.4 Malechai on 13 Mar 2008 - 16:59
(Ficman said @ #5.3)
(neufuse said @ #5.2)
(Davebo said @ #5.1)
(Ficman said @ #5)
Good Lord.... Who uses Realplayer anymore... If you haven't yet, stop using it...


Of course, the following is true as well....

"Good Lord.... Who uses Internet Explorer anymore... If you haven't yet, stop using it..."


can't say that when the majority of the market uses it I'd say over 85% of the world using it is a majority...



I'd love to know where that % comes from, nobody I know allows it on any of the networks they manage nor do we allow it.

Source please?


this actually got my interest as well so I googled it. I found lots here: http://en.wikipedia.org/wiki/Usage_share_of_web_browsers
#6 morphen on 13 Mar 2008 - 12:04
Just stop using realplayer, just who uses this anymore?
#7 hewitt s. on 13 Mar 2008 - 12:32
People still use RealPlayer?
#8 hewitt s. on 13 Mar 2008 - 12:34
I'm waiting for the next article in the series: "Stop using Windows 95"
(1 reply) #9 Havin_it on 13 Mar 2008 - 12:42
Oh look, a RealPlayer article and its obligatory tail of "who uses this anymore" posts, that's far more useful than commenting on the actual content of the article isn't it? Oafs.

I really can't understand this reflex behavior every time RP is mentioned. Yes, we get it, it's not widely used anymore, and you don't like it / never liked it. Is it really worth telling everyone so, yet again? I just don't see what anyone gains from that.

FWIW, I find RP quite useful on Linux (and Windows, when at work). I don't agree whatsoever that it's bloated, compare its resource usage with WMP10 FFS. The unnecessary UI components and the legendary (but much overhyped IMHO) adware content can be disabled in about a minute on first setup, and then you just have a nice small-form-factor media and streaming client that, in my experience, works quite reliably for as long as I need it.

It may not be very cutting-edge these days, but it still seems to do its job quite adequately. Interesting to note that when I tried going to YouTube's mobile site on my new Nokia's mobile browser the other day, the video didn't load in the included MiniFlashPlayer, but in RealPlayer! So I guess it's not quite out of the game yet, eh?

Anyway, on-topic for a moment... who on earth uses Internet Explorer these days? <ducks>
#9.1 dandin1 on 13 Mar 2008 - 13:43
I think that kind of comment is relatively justified, if you consider it a sarcastic response to the report's suggestion that users stop using their browsers because of a flaw in another program.
#10 rdmiller on 13 Mar 2008 - 12:55
It is on topic. The original, original source for this article is an blog post from the Internet Nazis at SANS, who have no clue that no one uses RealPlayer anymore and whose solution to everything is to switch to Firefox.
#11 Screaming Slave on 13 Mar 2008 - 13:52
I truly cannot think of one person that uses this thing anymore, nor have I seen links to any RP-based videos on the web.
#12 Xenomorph on 13 Mar 2008 - 13:59
I have to add my "who uses RealPlayer?" comment as well.

The only times I've seen RealPlayer is when it comes pre-installed on a computer.

What point is there in the software? Flash / WMV / QT is pretty much the standard for Internet video.

I actually *love* the fact that WMV use is dropping as well in favor of more Flash based videos.

(1 reply) #13 Adequate on 13 Mar 2008 - 14:14
And for those who'd need to read RealPlayer files, there's always Real Alternative...
#13.1 hewitt s. on 13 Mar 2008 - 15:20
(Adequate said @ #13)
And for those who'd need to read RealPlayer files, there's always Real Alternative...


Real Alternative is a must have for those rare occasions you need to view RM content. I also recommend Quicktime Alternative by the same author.
#14 _dandy_ on 13 Mar 2008 - 14:21
I've stopped installing RealPlayer years ago. I can't say I care about any of the alternatives that can play the streams either. If a site only offers Real, it's their loss, not mine, and they need to get with the program.
#15 +mrbester on 13 Mar 2008 - 14:31
If this is indeed a flaw within the ActiveX implementation for Internet Explorer then other ActiveX components could exhibit the same behaviour. If (as is more likely) it is a flaw within Real's crappy out of date plugin then perhaps they ought to fix it instead of whining about possible overflows in IE.
#16 C_Guy on 13 Mar 2008 - 15:20
Real Player says stop using Internet Explorer?

It's so hard to choose. Do I keep the best web browser for Windows or a crummy media player I haven't launched in years?

Now, let me think about it.....
#17 Skwerl on 13 Mar 2008 - 15:35
The bad taste that Real left in people's mouths years ago still abounds today. They should have mended their evil ways years ago, but didn't. Shouldn't the question be "why would anyone use use RealPlayer," rather than "does anyone actually use it anymore?"
#18 TechMedik on 13 Mar 2008 - 18:41
While I don't use realplayer, I do use rhapsody. I don't find it bad at all. People don't realize that rhapsody is the 2nd biggest non-itunes store behind amazon. It's bigger than napster and zune marketplace.
#19 morphen on 14 Mar 2008 - 07:58
Crapware,errorware,cachingware,bloatware... any more names for realplayer?
#20 ]SK[ on 14 Mar 2008 - 18:49
Ah RealPlayer... my most hated application. How it survives is beyond me.
(2 replies) #21 Skyfrog on 14 Mar 2008 - 21:06
Do any web sites still use Real? Why is this company still around?
#21.1 Jugalator on 15 Mar 2008 - 00:24
Because web sites still use Real. I don't know why, they probably give them good (cheap) licensing deals or something.
#21.2 brettuk on 16 Mar 2008 - 13:56
(Jugalator said @ #21.1)
Because web sites still use Real. I don't know why, they probably give them good (cheap) licensing deals or something.


Unfortunately the BBC still insists on using real player for some things on their website, although thankfully they seem to be moving away and going with WMP and flash these days...
#22 Jugalator on 15 Mar 2008 - 00:23
Good I don't use either of those crappy apps on Windows then. :-p

Commenting has either been disabled on this article or you are not logged in. Click here to login or register, its free!

Note: Anonymous commenting is disabled in order to keep the quality of responses to a high standard.

Advertisement (Why?)