Real Networks RealPlayer Directory Traversal Vulnerability
BID:4221
Info
Real Networks RealPlayer Directory Traversal Vulnerability
| Bugtraq ID: | 4221 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-0415 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 02 2002 12:00AM |
| Updated: | Jul 11 2009 10:56AM |
| Credit: | Reported by [email protected]. |
| Vulnerable: |
RealNetworks RealPlayer 6.0 Win32 RealNetworks RealPlayer 6.0 Unix |
| Not Vulnerable: | |
Discussion
Real Networks RealPlayer Directory Traversal Vulnerability
RealPlayer is a media player for Windows, Macintosh, Linux and Solaris. It has been reported that it is possible to traverse the directory structure of a host, leading to a potential disclosure of sensitive data.
It has been reported that RealPlayer uses a web server when playing streaming media files off the local system. Allegedly, submitting a HTTP GET request for the port RealPlayer listens on, along with '../' character sequences and a known file, could disclose the requested resource.
RealPlayer is a media player for Windows, Macintosh, Linux and Solaris. It has been reported that it is possible to traverse the directory structure of a host, leading to a potential disclosure of sensitive data.
It has been reported that RealPlayer uses a web server when playing streaming media files off the local system. Allegedly, submitting a HTTP GET request for the port RealPlayer listens on, along with '../' character sequences and a known file, could disclose the requested resource.
Exploit / POC
Real Networks RealPlayer Directory Traversal Vulnerability
No exploit code required.
No exploit code required.
Solution / Fix
Real Networks RealPlayer Directory Traversal Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Real Networks RealPlayer Directory Traversal Vulnerability
References:
References:
- RealServer Product Homepage (Real Networks)