RealNetworks RealOne Player And RealPlayer Remote Arbitrary File Deletion Vulnerability
BID:11308
Info
RealNetworks RealOne Player And RealPlayer Remote Arbitrary File Deletion Vulnerability
| Bugtraq ID: | 11308 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 29 2004 12:00AM |
| Updated: | Sep 29 2004 12:00AM |
| Credit: | Discovery is credited to NGSSoftware Insight Security Research <[email protected]>. |
| Vulnerable: |
RealNetworks RealPlayer 10 Japanese RealNetworks RealPlayer 10 German RealNetworks RealPlayer 10 English RealNetworks RealPlayer 10.5 v6.0.12.1040 RealNetworks RealPlayer 10.5 Beta v6.0.12.1016 RealNetworks RealPlayer 10.5 RealNetworks RealPlayer 10.0 BETA RealNetworks RealPlayer 10.0 v6.0.12.690 RealNetworks RealOne Player 2.0 RealNetworks RealOne Player 1.0 |
| Not Vulnerable: |
RealNetworks RealPlayer for Palm OS RealNetworks RealPlayer 10 for Mac OS RealNetworks RealPlayer 10.5 v6.0.12.1053 RealNetworks RealOne Player for Palm OS RealNetworks Helix Player for Symbian |
Discussion
RealNetworks RealOne Player And RealPlayer Remote Arbitrary File Deletion Vulnerability
RealPlayer and RealOne Player are prone to a vulnerability that may allow an attacker to delete arbitrary files on the client computer.
Reportedly, if the file to be downloaded already exists on the affected computer, the application proceeds to delete the file. Directory traversal sequences may be used to delete arbitrary files as well.
This issue can be exploited with a malicious Web page.
RealPlayer and RealOne Player are prone to a vulnerability that may allow an attacker to delete arbitrary files on the client computer.
Reportedly, if the file to be downloaded already exists on the affected computer, the application proceeds to delete the file. Directory traversal sequences may be used to delete arbitrary files as well.
This issue can be exploited with a malicious Web page.
Exploit / POC
RealNetworks RealOne Player And RealPlayer Remote Arbitrary File Deletion Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
RealNetworks RealOne Player And RealPlayer Remote Arbitrary File Deletion Vulnerability
Solution:
The vendor has released updates dealing with this issue. Please see the referenced advisory for more information on obtaining the updated packages.
Solution:
The vendor has released updates dealing with this issue. Please see the referenced advisory for more information on obtaining the updated packages.
References
RealNetworks RealOne Player And RealPlayer Remote Arbitrary File Deletion Vulnerability
References:
References:
- Home Page (Real Networks)
- RealNetworks, Inc. Releases Update to Address Security Vulnerabilities. (Real Networks)
- RealPlayer Arbitrary File Deletion Vulnerability (#NISR19012005f) ("NGSSoftware Insight Security Research"
)