Two exploits have been identified in the Linux RealPlayer client.
RealNetworks states:
RealNetworks, Inc. has addressed recently discovered
security vulnerabilities that offered the potential for
an attacker to run arbitrary or malicious code on a
customer's machine. RealNetworks has received no reports
of machines compromised as a result of the now-remedied
vulnerabilities. RealNetworks takes all security
vulnerabilities very seriously.
The specific exploits were:
-
Exploit 1: To fashion a malicious WAV
file to cause a buffer overflow which could have allowed
an attacker to execute arbitrary code on a customer's
machine.
-
Exploit 2: To fashion a malicious
SMIL file to cause a buffer overflow which could have
allowed an attacker to execute arbitrary code on a
customer's machine.