PT-2003-2454 · Real · Realone Enterprise Desktop+1
Published
2003-12-31
·
Updated
2017-08-17
·
CVE-2003-1509
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
RealOne Enterprise Desktop version 6.0.11.774
RealOne Player version 2.0
RealOne Player versions 6.0.11.818 through 6.0.11.853
Description
The issue allows remote attackers to execute arbitrary script in the local security zone. This is achieved by embedding script in a temp file before the temp file is executed by the default web browser.
Recommendations
For RealOne Enterprise Desktop version 6.0.11.774, update to a version that contains a fix for this issue.
For RealOne Player version 2.0, update to a version that contains a fix for this issue.
For RealOne Player versions 6.0.11.818 through 6.0.11.853, update to a version that contains a fix for this issue.
As a temporary workaround, consider restricting the execution of temp files by the default web browser until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Realone Enterprise Desktop
Realone Player