Apple iTunes Memory Corruption Vulnerability
Last Update Date:
19 Sep 2013 12:18
Release Date:
19 Sep 2013
4028
Views
RISK: High Risk
TYPE: Clients - Audio & Video
A vulnerability has been identified in Apple iTunes. A remote user can cause arbitrary code to be executed on the target user's system.
A remote user can create specially crafted HTML that, when loaded by the target user, will invoke the iTunes ActiveX control and trigger a memory corruption error to execute arbitrary code on the target system.
Impact
- Remote Code Execution
System / Technologies affected
- Versions prior to 11.1
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- The vendor has issued a fix (11.1).
Vulnerability Identifier
Source
Related Link
Share with