|
RealOne Player SMIL Cross-Site Scripting Vulnerability
|
|
|
|
|
Secunia Advisory:
|
SA9584
|
|
|
Release Date:
|
2003-08-21
|
|
Last Update:
|
2004-01-08
|
|
|
Critical:
|

Moderately critical
|
|
Impact:
|
Cross Site Scripting System access
|
|
Where:
|
From remote
|
|
Solution Status:
|
Vendor Patch
|
|
| Software: | RealOne Desktop Manager RealOne Enterprise Desktop RealOne Player 1.x RealOne Player 2.x
|
|
|
Want to know the next time vulnerabilities are fixed in this product? - Companies can be alerted via email and SMS! |
|
|
Description: RealNetworks has reported a vulnerability in RealOne Player, which can be exploited by malicious people to execute arbitrary code.
The vulnerability is caused due to an error in the handling of SMIL files. This can be exploited to execute script code in the context of an arbitrary domain or the local system by constructing a specially crafted SMIL file and tricking a user into executing it.
The vulnerability has been reported to affect the following versions:
* RealOne Player (English only)
* RealOne Player v2 for Windows (all language versions)
* RealOne Enterprise Desktop (all versions, standalone and as configured by the RealOne Desktop Manager)
Arman Nayyeri has reported a variant of the vulnerability, allowing malicious SMIL files to bypass the original patch by prefixing the "javascript:" URI handler with a "file:" URI handler. This has been reported to affect RealOne Player version 1 and 2; other products may also be affected.
Do you have this product installed on your home computer? Scan using the free Personal Software Inspector. Check if a vulnerable version is installed on computers in your corporate network, using the Network Software Inspector.
Solution: NOTE: The update below does not fix the variant. Do not open SMIL files from untrusted sources.
Updates for RealOne Player can be installed by using the "Check for Update" feature.
Update RealOne Desktop Manager:
http://licensekey.realnetworks.c...ms/products/tools/rdm/index.html
Update RealOne Enterprise Desktop:
http://forms.real.com/rnforms/products/tools/red/index.html
Provided and/or discovered by: KrazySnake, DigitalPranksters.
Arman Nayyeri.
Changelog: 2003-08-29: Updated "Description" section.
2004-01-08: Added information reported by Arman Nayyeri about un-fixed variant.
Original Advisory: http://www.service.real.com/help/faq/security/securityupdate_august2003.html
|
|
|
|
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|
|
|
|
16 Related Secunia Security Advisories, displaying 10
|
|
|
1. RealPlayer/RealOne/HelixPlayer Multiple Buffer Overflows
|
|
2. RealPlayer Playlist Handling Buffer Overflow Vulnerability
|
|
3. RealNetworks Products Multiple Buffer Overflow Vulnerabilities
|
|
4. RealPlayer/RealOne/HelixPlayer "rm" and "rjs" File Handling Buffer Overflow
|
|
5. RealOne / RealPlayer / Helix Player / Rhapsody Multiple Vulnerabilities
|
|
6. Realplayer/RealOne RAM File Processing Buffer Overflow Vulnerability
|
|
7. RealPlayer WAV and SMIL File Handling Buffer Overflows
|
|
8. RealPlayer/RealOne "DUNZIP32.dll" Buffer Overflow Vulnerability
|
|
9. RealOne Player / RealPlayer / Helix Player Multiple Vulnerabilities
|
|
10. RealPlayer Multiple Buffer Overflow Vulnerabilities
|
Show all related advisories
|
|
|
Send Feedback to Secunia
|
|
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.
|
|
|
|