Apple iTunes Code Execution and Privilege Escalation Vulnerabilities
RISK: Medium Risk
Multiple vulnerabilitieshave been identified in Apple iTunes, which could be exploited by remote attackers to cause a denial of service or compromise a vulnerable system, or by local attackers to obtain elevated privileges.
1. Due to various errors exist in ColorSync and ImageIO when processing malformed images, which could be exploited by attackers to execute arbitrary code.
2. Due to an infinite loop exists in the handling of MP4 files, which could be exploited by attackers to crash an affected application.
3. Due to a race condition exists in the iTunes for Windows installation package, which may allow a local user to modify a file that is then executed with SYSTEM privileges.
Impact
- Denial of Service
- Remote Code Execution
System / Technologies affected
- Apple iTunes versions prior to 9.1
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Upgrade to Apple iTunes version 9.1 :
- http://www.apple.com/itunes/download/
Vulnerability Identifier
Source
Related Link
Share with