Apple iTunes "itms:" URI Handling Remote Buffer Overflow Vulnerability
RISK: Medium Risk
A vulnerability has been identified in Apple iTunes, which could be exploited by remote attackers to cause a denial of service or compromise a vulnerable system. This issue is caused by a stack overflow error when processing a specially crafted "itms:" URL, which could be exploited by remote attackers to crash an affected application or execute arbitrary code by tricking a user into visiting a malicious web page.
Impact
- Denial of Service
- Remote Code Execution
System / Technologies affected
- Apple iTunes versions prior to 8.2
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Upgrade to Apple iTunes version 8.2 :
http://www.apple.com/itunes/download
Vulnerability Identifier
Source
Related Link
Share with