Directory traversal vulnerability in the parsing of Skin file names in RealPlayer 10.5 (6.0.12.1040) and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in an RJS filename.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Realone_player | Realnetworks | 1.0 (including) | 1.0 (including) |
Realone_player | Realnetworks | 2.0 (including) | 2.0 (including) |
Realplayer | Realnetworks | 10.0 (including) | 10.0 (including) |
Realplayer | Realnetworks | 10.0-beta (including) | 10.0-beta (including) |
Realplayer | Realnetworks | 10.5 (including) | 10.5 (including) |