PT-2004-2698 · Realnetworks · Realone Player

Published

2004-12-31

·

Updated

2017-07-11

·

CVE-2004-1798

CVSS v2.0

5.1

Medium

VectorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions RealOne player version 6.0.11.868
Description The issue allows remote attackers to execute arbitrary script in the "My Computer" zone. This is achieved via a Synchronized Multimedia Integration Language (SMIL) presentation with a "file:javascript:" URL. The script is executed in the security context of the previously loaded URL.
Recommendations For RealOne player version 6.0.11.868, consider disabling the execution of SMIL presentations with "file:javascript:" URLs as a temporary workaround until a patch is available. Restrict access to SMIL files to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-1798

Affected Products

Realone Player