PT-2005-3785 · Realnetworks · Realplayer+1
Published
2005-11-18
·
Updated
2011-05-19
·
CVE-2005-2936
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
RealPlayer versions 6.0.12.1040 through 6.0.12.1348
RealPlayer 10
RealOne Player v2
RealOne Player v1
RealPlayer 8 before 20060322
Description
The issue allows local users to potentially gain privileges through a malicious file.
Recommendations
For RealPlayer versions 6.0.12.1040 through 6.0.12.1348, update to a version outside of this range.
For RealPlayer 10, consider upgrading to a newer version.
For RealOne Player v2 and RealOne Player v1, upgrade to a newer version of the player.
For RealPlayer 8, update to a version released after 20060322.
As a temporary workaround, consider restricting the execution of files from untrusted locations to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Realone Player
Realplayer