CERT-In Vulnerability Note
CIVN-2011-0178
Apple iTunes Update Validation Flaw Vulnerability
Original Issue Date:November 22, 2011
Severity Rating: MEDIUM
Systems Affected
- Apple iTunes version prior to 10.5.1
Overview
A vulnerability has been reported in Apple iTunes. A remote user may be able to cause arbitrary code to be executed on the target user's system in certain cases.
Description
A vulnerability has been reported in Apple iTunes. A remote user with the ability to conduct a man-in-the-middle attack can return a specially crafted response to cause the target user to download arbitrary code when the target user selects download iTunes.
Solution
Upgrade to "iTunes10.5.1.dmg"
http://support.apple.com/kb/HT5030
Vendor Information
Apple
http://support.apple.com/kb/HT5030
References
Securitytracker
http://securitytracker.com/id/1026323
Tenable Network Security
http://www.nessus.org/plugins/index.php?view=single&id=56873
CVE Name
CVE-2008-3434
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|