Real Player Content?

(imported topic written by snoczp91)

Does BigFix publish content for Real Player vulnerabilities, or upgrades to Real Player versions?

Thanks,

(imported comment written by JackCoates91)

Yes, there’s a definition in Updates for Windows Applications.

(imported comment written by snoczp91)

I see only 2 updates under Real Networks when I sort fixlets by source - Real Player 11 and Real Player 11 French.

Shouldn’t there be much more and newer content than that?

It looks like we are already subscribed to their site.

(imported comment written by JackCoates91)

Please correct me if I’m wrong, but it’s my understanding that Real doesn’t make security patches for the older versions available (e.g. 4.0.x to 4.0.y). This means that we can only offer upgrade to the current version (e.g. x.x.x to 11.0.0.674), which is what the Real Player 11 fixlet does.

(imported comment written by snoczp91)

The most recent content on our BES server is dated 7/1/2009, and is only for version 11 and the French version of 11, and updates RealPlayer to the version (11.1.3 build 6.0.14.955).

From Real Networks’ web site, the newest free version is now called Real Player SP.

(imported comment written by JackCoates91)

I looked into this a little deeper, you’re right. We derived this content from the SANS top 20, which is no longer maintained by SANS. I’ve entered a bug to update the content to version 12.0.0.343. Sorry for the confusion. In the meantime, this fixlet will detect systems that are out of date:

exists regapp 
"realplay.exe" whose (version of it < 
")