vendor:
iTunes
by:
Gjoko 'LiquidWorm' Krstic
7,8
CVSS
HIGH
Heap Buffer Overflow
119
CWE
Product Name: iTunes
Affected Version From: 10.6.1.7
Affected Version To: 10.6.0.40
Patch Exists: YES
Related CWE: N/A
CPE: a:apple:itunes
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Microsoft Windows XP
2012
Apple iTunes 10.6.1.7 M3U Playlist File Walking Heap Buffer Overflow
The vulnerability is caused due to a boundary error in the processing of a playlist file, which can be exploited to cause a heap based buffer overflow when a user opens e.g. a specially crafted .M3U file. Successful exploitation could allow execution of arbitrary code on the affected node.
Mitigation:
Update to the latest version of iTunes