Skip to main content

Apple iTunes Code Execution and Privilege Escalation Vulnerabilities

Last Update Date: 28 Jan 2011 Release Date: 1 Apr 2010 5558 Views

RISK: Medium Risk

Multiple vulnerabilitieshave been identified in Apple iTunes, which could be exploited by remote attackers to cause a denial of service or compromise a vulnerable system, or by local attackers to obtain elevated privileges.

1. Due to various errors exist in ColorSync and ImageIO when processing malformed images, which could be exploited by attackers to execute arbitrary code.

2. Due to an infinite loop exists in the handling of MP4 files, which could be exploited by attackers to crash an affected application.

3. Due to a race condition exists in the iTunes for Windows installation package, which may allow a local user to modify a file that is then executed with SYSTEM privileges.


Impact

  • Denial of Service
  • Remote Code Execution

System / Technologies affected

  • Apple iTunes versions prior to 9.1

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.


Vulnerability Identifier


Source


Related Link