CVE-2004-0273
Summary
| CVE | CVE-2004-0273 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2004-11-23 05:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Directory traversal vulnerability in RealOne Player, RealOne Player 2.0, and RealOne Enterprise Desktop allows remote attackers to upload arbitrary files via an RMP file that contains .. (dot dot) sequences in a .rjs skin file. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:M/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Realnetworks | Realone Desktop Manager | All | All | All | All |
| Application | Realnetworks | Realone Enterprise Desktop | 6.0.11.774 | All | All | All |
| Application | Realnetworks | Realone Player | 1.0 | All | All | All |
| Application | Realnetworks | Realone Player | 2.0 | All | All | All |
| Application | Realnetworks | Realone Player | 2.0 | All | win | All |
| Application | Realnetworks | Realone Player | 6.0.11.818 | All | All | All |
| Application | Realnetworks | Realone Player | 6.0.11.830 | All | All | All |
| Application | Realnetworks | Realone Player | 6.0.11.841 | All | All | All |
| Application | Realnetworks | Realone Player | 6.0.11.853 | All | All | All |
| Application | Realnetworks | Realone Player | 6.0.11.868 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| RealPlayer/RealOne Player RMP Skin File Handler Directory Traversal Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch, Vendor Advisory |
| Customer Support - Real Security Updates | af854a3a-2127-422b-91ae-364da2661108 | service.real.com | Patch, Vendor Advisory |
| marc.info | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| US-CERT Vulnerability Note VU#514734 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.