Saturday, July 24, 2010

iTunes 9.2.1 : APPLE-SA-2010-07-19-1 iTunes 9.2.1 vulnerabilities

Users of iTunes 9.2.1 please be advised of an APPLE-SA-2010-07-19-1 iTunes 9.2.1 vulnerabilities that has been identified.

To view this vulnerability, possible remedies, and others please check out the Security Advisories at Critical Watch (http://criticalwatch.com/support/security-advisories.aspx)

Amplify’d from www.criticalwatch.com
APPLE-SA-2010-07-19-1: APPLE-SA-2010-07-19-1 iTunes 9.2.1
Tunes 9.2.
iTunes 9.2.1
iTunes

CVE-ID: CVE-2010-1777

Available for: Windows 7, Vista, XP SP2 or later

Impact: Visiting a maliciously crafted website may lead to an

unexpected application termination or arbitrary code execution

Description: A buffer overflow exists in the handling of "itpc:"

URLs. Accessing a maliciously crafted "itpc:" URL may lead to an

unexpected application termination or arbitrary code execution. This

issue is addressed through improved bounds checking. Credit to Clint

Ruoho of Laconic Security for reporting this issue.Read more at www.criticalwatch.com
 

No comments:

Post a Comment