CVE-2005-0348: Low severity RealNetworks Realarcade vulnerability
Published Feb 10, 2005
·Updated
Directory traversal vulnerability in RealArcade 1.2.0.994 allows remote attackers to delete arbitrary files via an RGP file with a .. (dot dot) in the FILENAME tag.
Affected Software
1 affected component
RealNetworks Realarcade<=1.2.0.994
Event History
Feb 10, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-0348?
CVE-2005-0348 is considered a moderate to high severity vulnerability due to its potential for allowing unauthorized file deletion.
2
How do I fix CVE-2005-0348?
To fix CVE-2005-0348, you should upgrade RealArcade to a version above 1.2.0.994 that does not contain this vulnerability.
3
What does CVE-2005-0348 allow attackers to do?
CVE-2005-0348 allows remote attackers to exploit directory traversal to delete arbitrary files on the server.
4
Which version of RealArcade is affected by CVE-2005-0348?
CVE-2005-0348 affects RealArcade version 1.2.0.994 and earlier.
5
Is there a workaround for CVE-2005-0348?
As a temporary workaround for CVE-2005-0348, you can restrict file deletions by configuring server permissions, but upgrading is the best solution.