Real Networks RealJukebox Predictable File Extraction Vulnerability

BID:5210

Info

Real Networks RealJukebox Predictable File Extraction Vulnerability

Bugtraq ID: 5210
Class: Design Error
CVE:
Remote: Yes
Local: No
Published: Jul 11 2002 12:00AM
Updated: Jul 11 2002 12:00AM
Credit: This issue was announced by Real Networks.
Vulnerable: RealNetworks RealOne Player Gold for Windows 6.0.10 .505
- Microsoft Windows 2000 Advanced Server SP2
- Microsoft Windows 2000 Advanced Server SP1
- Microsoft Windows 2000 Advanced Server
- Microsoft Windows 2000 Datacenter Server SP2
- Microsoft Windows 2000 Datacenter Server SP1
- Microsoft Windows 2000 Datacenter Server
- Microsoft Windows 2000 Professional SP2
- Microsoft Windows 2000 Professional SP1
- Microsoft Windows 2000 Professional
- Microsoft Windows 2000 Server SP2
- Microsoft Windows 2000 Server SP1
- Microsoft Windows 2000 Server
- Microsoft Windows 95 SR2
- Microsoft Windows 95
- Microsoft Windows 98
- Microsoft Windows 98SE
- Microsoft Windows ME
- Microsoft Windows NT Enterprise Server 4.0 SP6a
- Microsoft Windows NT Enterprise Server 4.0 SP6
- Microsoft Windows NT Enterprise Server 4.0 SP5
- Microsoft Windows NT Enterprise Server 4.0 SP4
- Microsoft Windows NT Enterprise Server 4.0 SP3
- Microsoft Windows NT Enterprise Server 4.0 SP2
- Microsoft Windows NT Enterprise Server 4.0 SP1
- Microsoft Windows NT Enterprise Server 4.0
- Microsoft Windows NT Server 4.0 SP6a
- Microsoft Windows NT Server 4.0 SP6
- Microsoft Windows NT Server 4.0 SP5
- Microsoft Windows NT Server 4.0 SP4
- Microsoft Windows NT Server 4.0 SP3
- Microsoft Windows NT Server 4.0 SP2
- Microsoft Windows NT Server 4.0 SP1
- Microsoft Windows NT Server 4.0
- Microsoft Windows NT Workstation 4.0 SP6a
- Microsoft Windows NT Workstation 4.0 SP6
- Microsoft Windows NT Workstation 4.0 SP5
- Microsoft Windows NT Workstation 4.0 SP4
- Microsoft Windows NT Workstation 4.0 SP3
- Microsoft Windows NT Workstation 4.0 SP2
- Microsoft Windows NT Workstation 4.0 SP1
- Microsoft Windows NT Workstation 4.0
- Microsoft Windows XP Home
- Microsoft Windows XP Professional
RealNetworks RealJukebox 2 Plus for Windows 1.0.2 .379
RealNetworks RealJukebox 2 Plus for Windows 1.0.2 .340
RealNetworks RealJukebox 2 for Windows 1.0.2 .379
RealNetworks RealJukebox 2 for Windows 1.0.2 .340
Not Vulnerable:

Discussion

Real Networks RealJukebox Predictable File Extraction Vulnerability

Real Software has announced a vulnerability in RealJukebox2 and Real Player Gold. When skin files are opened, the files comprising the skin are extracted to a known location on client filesystems. This may provide a remote attacker with the ability to plant a file on a victim filesystem by transmitting a seemingly benign skin. The presence of a file in a specific location may provide the attacker the ability carry out more complex attacks, such as creating a "file://" link to malicious content in a skinfile and enticing the user who downloaded the skin to visit the link.

The ability to plant a file on the victim filesystem may also be levaraged in conjunction with other vulnerabilities such as that described by Bugtraq ID 3867.

The vendor has addressed this issue in affected products by making the location of skinfile extractions less predictable.

Exploit / POC

Real Networks RealJukebox Predictable File Extraction Vulnerability

Detailed exploit instructions have been provided by UNYUN ([email protected]). See referenced message for further details.

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report