Skip to main content

Apple iTunes Credentials Access Vulnerability

Last Update Date: 19 May 2014 10:11 Release Date: 19 May 2014 3450 Views

RISK: High Risk

TYPE: Clients - Audio & Video

TYPE: Audio & Video

A vulnerability has been identified in Apple iTunes, which can be exploited to obtain credentials.

 

An attacker could strip security settings from the cookie by forcing the connection to close before the security settings were sent, and then obtain the value of the unprotected cookie.


Impact

  • Information Disclosure

System / Technologies affected

  • Versions prior to 11.2 for Windows 8, 7, Vista, XP

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • The vendor has issued a fix (iTunes 11.2).

Vulnerability Identifier


Source


Related Link