Apple iTunes Playlist Processing Buffer Overflow Vulnerability
Last Update Date:
28 Jan 2011
Release Date:
23 Sep 2009
5519
Views
RISK: Medium Risk
A vulnerability has been identified in Apple iTunes, which could be exploited by attackers to compromise a vulnerable system. This issue is caused by a buffer overflow error when processing playlist ".pls" files containing malformed data, which could be exploited by attackers to crash an affected application or execute arbitrary code by tricking a user into opening a malicious playlist file.
Impact
- Remote Code Execution
System / Technologies affected
- Apple iTunes versions prior to 9.0.1
Solutions
- Upgrade to Apple iTunes version 9.0.1 :
http://www.apple.com/itunes/download/
Vulnerability Identifier
Source
Related Link
Share with