Real Networks RealJukebox Predictable File Extraction Vulnerability
BID:5210
Info
Real Networks RealJukebox Predictable File Extraction Vulnerability
| Bugtraq ID: | 5210 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 11 2002 12:00AM |
| Updated: | Jul 11 2002 12:00AM |
| Credit: | This issue was announced by Real Networks. |
| Vulnerable: |
RealNetworks RealOne Player Gold for Windows 6.0.10 .505 RealNetworks RealJukebox 2 Plus for Windows 1.0.2 .379 RealNetworks RealJukebox 2 Plus for Windows 1.0.2 .340 RealNetworks RealJukebox 2 for Windows 1.0.2 .379 RealNetworks RealJukebox 2 for Windows 1.0.2 .340 |
| Not Vulnerable: | |
Discussion
Real Networks RealJukebox Predictable File Extraction Vulnerability
Real Software has announced a vulnerability in RealJukebox2 and Real Player Gold. When skin files are opened, the files comprising the skin are extracted to a known location on client filesystems. This may provide a remote attacker with the ability to plant a file on a victim filesystem by transmitting a seemingly benign skin. The presence of a file in a specific location may provide the attacker the ability carry out more complex attacks, such as creating a "file://" link to malicious content in a skinfile and enticing the user who downloaded the skin to visit the link.
The ability to plant a file on the victim filesystem may also be levaraged in conjunction with other vulnerabilities such as that described by Bugtraq ID 3867.
The vendor has addressed this issue in affected products by making the location of skinfile extractions less predictable.
Real Software has announced a vulnerability in RealJukebox2 and Real Player Gold. When skin files are opened, the files comprising the skin are extracted to a known location on client filesystems. This may provide a remote attacker with the ability to plant a file on a victim filesystem by transmitting a seemingly benign skin. The presence of a file in a specific location may provide the attacker the ability carry out more complex attacks, such as creating a "file://" link to malicious content in a skinfile and enticing the user who downloaded the skin to visit the link.
The ability to plant a file on the victim filesystem may also be levaraged in conjunction with other vulnerabilities such as that described by Bugtraq ID 3867.
The vendor has addressed this issue in affected products by making the location of skinfile extractions less predictable.
Exploit / POC
Real Networks RealJukebox Predictable File Extraction Vulnerability
Detailed exploit instructions have been provided by UNYUN ([email protected]). See referenced message for further details.
Detailed exploit instructions have been provided by UNYUN ([email protected]). See referenced message for further details.