| |||||||||||||
| Test ID: | 1.3.6.1.4.1.25623.1.0.801409 |
| Category: | Buffer overflow |
| Title: | Apple iTunes 'itpc:' URI Buffer Overflow Vulnerability |
| Summary: | Check for the version of Apple iTunes |
| Description: | Overview: This host has iTunes installed, which is prone to buffer overflow vulnerability. Vulnerability Insight: The flaw is exists in the handling of 'itpc:' URL, when loaded by the user will trigger a buffer overflow and execute arbitrary code on the target system. Impact: Successful exploitation could allow the attacker to execute arbitrary code in the context of an application. Failed exploit attempts will result in a denial-of-service condition. Impact Level: Application Affected Software/OS: Apple iTunes version prior to 9.2.1 Fix: Upgrade to Apple iTunes version 9.2.1 or later, For updates refer to http://www.apple.com/itunes/download/ References: http://isc.sans.edu/diary.html?storyid=9202 http://securitytracker.com/alerts/2010/Jul/1024220.html |
| Cross-Ref: |
BugTraq ID: 41789 Common Vulnerability Exposure (CVE) ID: CVE-2010-1777 http://lists.apple.com/archives/security-announce/2010//Jul/msg00000.html http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6988 |
| Copyright | Copyright (c) 2010 Greenbone Networks GmbH |
| This is only one of 32582 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |
|