PT-2005-2997 · Realnetworks+1 · Realone Player+2
Published
2005-06-28
·
Updated
2008-09-05
·
CVE-2005-2055
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
RealPlayer versions 8, 10, 10.5 (6.0.12.1040-1069)
RealOne Player versions 1, 2
Description:
The issue allows a remote malicious web server to create an arbitrary HTML file that executes an RM file via the default settings of earlier Internet Explorer browsers.
Recommendations:
For RealPlayer versions 8, 10, 10.5 (6.0.12.1040-1069), consider updating to a version outside of the specified range to mitigate the risk.
For RealOne Player versions 1, 2, consider updating to a version outside of the specified range to mitigate the risk.
As a temporary workaround, consider restricting the execution of RM files in the affected software until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Internet Explorer
Realone Player
Realplayer