Description
RealJukebox 2 1.0.2.340 and 1.0.2.379, and RealOne Player Gold 6.0.10.505, allows remote attackers to execute arbitrary script in the Local computer zone by inserting the script into the skin.ini file of an RJS archive, then referencing skin.ini from a web page after it has been extracted, which is parsed as HTML by Internet Explorer or other Microsoft-based web readers.
Products
- RealNetworks RealJukebox 2 1.0.2.340
- RealNetworks RealJukebox 2 1.0.2.379
- RealNetworks RealJukebox 2 Plus 1.0.2.340
- RealNetworks RealJukebox 2 Plus 1.0.2.379
- RealNetworks RealOne Player 6.0.10.505 Gold
Questions to Ask Vendors
- Can you confirm whether your systems are affected by CVE-2002-1015, and if so, what steps are you currently taking to mitigate this vulnerability?
- What is your estimated timeline for fully resolving CVE-2002-1015 in your products or services, and how will you communicate updates on this issue to us as your customer?
Recommended Actions
- Check out the advisory links provided below.
References