CVE-2005-0190: Low severity realnetworks realplayer vulnerability
Directory traversal vulnerability in RealPlayer 10.5 (6.0.12.1040) and earlier allows remote attackers to delete arbitrary files via a Real Metadata Packages (RMP) file with a FILENAME tag containing .. (dot dot) sequences in a filename that ends with a ? (question mark) and an allowed file extension (e.g. .mp3), which bypasses the check for the file extension.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-0190?
CVE-2005-0190 is considered a critical vulnerability due to its potential for remote file deletion.
How do I fix CVE-2005-0190?
To fix CVE-2005-0190, update RealPlayer to the latest version that addresses this vulnerability.
Which versions of RealPlayer are affected by CVE-2005-0190?
CVE-2005-0190 affects RealPlayer versions 10.5 and earlier, including RealOne Player 1.0 and 2.0.
What kind of attack does CVE-2005-0190 allow?
CVE-2005-0190 allows remote attackers to exploit directory traversal to delete arbitrary files.
Is there a workaround for CVE-2005-0190?
A temporary workaround for CVE-2005-0190 is to restrict the use of RealPlayer or disable it until a patch is applied.