PT-2004-2698 · Realnetworks · Realone Player

Publicado

2004-12-31

·

Atualizado

2017-07-11

·

CVE-2004-1798

CVSS v2.0

5.1

Média

VetorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions RealOne player version 6.0.11.868
Description The issue allows remote attackers to execute arbitrary script in the "My Computer" zone. This is achieved via a Synchronized Multimedia Integration Language (SMIL) presentation with a "file:javascript:" URL. The script is executed in the security context of the previously loaded URL.
Recommendations For RealOne player version 6.0.11.868, consider disabling the execution of SMIL presentations with "file:javascript:" URLs as a temporary workaround until a patch is available. Restrict access to SMIL files to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2004-1798

Produtos afetados

Realone Player