PT-2002-1469 · Realnetworks · Realplayer
Published
2002-06-11
·
Updated
2008-09-05
·
CVE-2002-0415
CVSS v2.0
1.7
Low
| Vector | AV:L/AC:L/Au:S/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
RealPlayer version 6.0.7
Description
A directory traversal issue in the web server used by RealPlayer may allow local users to read files accessible to RealPlayer by using a .. (dot dot) in an HTTP GET request to port 1275.
Recommendations
For RealPlayer version 6.0.7, consider restricting access to the web server or disabling it until a fix is available. Avoid using the .. (dot dot) notation in HTTP GET requests to port 1275 to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Realplayer