Skip to main content

Apple iTunes Memory Corruption Vulnerability

Last Update Date: 19 Sep 2013 12:18 Release Date: 19 Sep 2013 3276 Views

RISK: High Risk

TYPE: Clients - Audio & Video

TYPE: Audio & Video

A vulnerability has been identified in Apple iTunes. A remote user can cause arbitrary code to be executed on the target user's system.

 

A remote user can create specially crafted HTML that, when loaded by the target user, will invoke the iTunes ActiveX control and trigger a memory corruption error to execute arbitrary code on the target system.


Impact

  • Remote Code Execution

System / Technologies affected

  • Versions prior to 11.1

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.
  • The vendor has issued a fix (11.1).

Vulnerability Identifier


Source


Related Link