Apple iTunes Credentials Access Vulnerability
Last Update Date:
19 May 2014 10:11
Release Date:
19 May 2014
3450
Views
RISK: High Risk
TYPE: Clients - Audio & Video
A vulnerability has been identified in Apple iTunes, which can be exploited to obtain credentials.
An attacker could strip security settings from the cookie by forcing the connection to close before the security settings were sent, and then obtain the value of the unprotected cookie.
Impact
- Information Disclosure
System / Technologies affected
- Versions prior to 11.2 for Windows 8, 7, Vista, XP
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- The vendor has issued a fix (iTunes 11.2).
Vulnerability Identifier
Source
Related Link
Share with