vendor:
ITunes
by:
MC
N/A
CVSS
N/A
Buffer Overflow
119
CWE
Product Name: ITunes
Affected Version From: 4.7.0.42
Affected Version To: 4.7.0.42
Patch Exists: YES
Related CWE: CVE-2005-0043
CPE: a:apple:itunes:4.7
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
2005
Apple ITunes 4.7 Playlist Buffer Overflow
This module exploits a stack buffer overflow in Apple ITunes 4.7 build 4.7.0.42. By creating a URL link to a malicious PLS file, a remote attacker could overflow a buffer and execute arbitrary code. When using this module, be sure to set the URIPATH with an extension of '.pls'.
Mitigation:
Update to the latest version of Apple ITunes