Rhino
09-06-2007, 10:52 AM
Anyone using iTunes should upgrade to the latest version at the link below. iTunes comes bundled with QuickTime, so it's likely that you have it, even if you don't use it.
TITLE:
Apple iTunes Music File Buffer Overflow Vulnerability
SECUNIA ADVISORY ID:
SA26725
VERIFY ADVISORY:
http://secunia.com/advisories/26725/
CRITICAL:
Highly critical
IMPACT:
DoS, System access
WHERE:
From remote
SOFTWARE:
iTunes 7.x
http://secunia.com/product/12131/
iTunes 6.x
http://secunia.com/product/5882/
iTunes 5.x
http://secunia.com/product/7864/
iTunes 4.x
http://secunia.com/product/2916/
DESCRIPTION:
A vulnerability has been reported in Apple iTunes, which can be exploited by malicious people to compromise a user's system.
The vulnerability is caused due to an unspecified boundary error when processing album cover art. This can be exploited to cause a buffer overflow via a specially crafted music file.
Successful exploitation may allow execution of arbitrary code.
The vulnerability is reported in versions prior to 7.4.
SOLUTION:
Update to version 7.4.
iTunes 7.4 for Mac:
http://www.apple.com/support/downloads/itunes74formac.html
iTunes 7.4 for Windows:
http://www.apple.com/support/downloads/itunes74forwindows.html
PROVIDED AND/OR DISCOVERED BY:
The vendor credits David Thiel, iSEC Partners
ORIGINAL ADVISORY:
http://docs.info.apple.com/article.html?artnum=306404
TITLE:
Apple iTunes Music File Buffer Overflow Vulnerability
SECUNIA ADVISORY ID:
SA26725
VERIFY ADVISORY:
http://secunia.com/advisories/26725/
CRITICAL:
Highly critical
IMPACT:
DoS, System access
WHERE:
From remote
SOFTWARE:
iTunes 7.x
http://secunia.com/product/12131/
iTunes 6.x
http://secunia.com/product/5882/
iTunes 5.x
http://secunia.com/product/7864/
iTunes 4.x
http://secunia.com/product/2916/
DESCRIPTION:
A vulnerability has been reported in Apple iTunes, which can be exploited by malicious people to compromise a user's system.
The vulnerability is caused due to an unspecified boundary error when processing album cover art. This can be exploited to cause a buffer overflow via a specially crafted music file.
Successful exploitation may allow execution of arbitrary code.
The vulnerability is reported in versions prior to 7.4.
SOLUTION:
Update to version 7.4.
iTunes 7.4 for Mac:
http://www.apple.com/support/downloads/itunes74formac.html
iTunes 7.4 for Windows:
http://www.apple.com/support/downloads/itunes74forwindows.html
PROVIDED AND/OR DISCOVERED BY:
The vendor credits David Thiel, iSEC Partners
ORIGINAL ADVISORY:
http://docs.info.apple.com/article.html?artnum=306404