CVE Vulnerabilities

CVE-2005-0192

Published: Oct 06, 2004 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.6 LOW
AV:N/AC:H/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Directory traversal vulnerability in the parsing of Skin file names in RealPlayer 10.5 (6.0.12.1040) and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in an RJS filename.

Affected Software

NameVendorStart VersionEnd Version
Realone_playerRealnetworks1.0 (including)1.0 (including)
Realone_playerRealnetworks2.0 (including)2.0 (including)
RealplayerRealnetworks10.0 (including)10.0 (including)
RealplayerRealnetworks10.0-beta (including)10.0-beta (including)
RealplayerRealnetworks10.5 (including)10.5 (including)

References