Apple iTunes "itpc:" URL Processing Buffer Overflow Vulnerability
Last Update Date:
28 Jan 2011
Release Date:
21 Jul 2010
5387
Views
RISK: Medium Risk
A vulnerability has been identified in Apple iTunes, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by a buffer overflow error when processing malformed "itpc:" URLs, which could be exploited by attackers to crash an affected application or execute arbitrary code by tricking a user into following a specially crafted URL.
Impact
- Remote Code Execution
System / Technologies affected
- Apple iTunes versions prior to 9.2.1
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Upgrade to Apple iTunes version 9.2.1:
http://www.apple.com/itunes/download/
Vulnerability Identifier
Source
Related Link
Share with