vulnerability in iTunes
August 21st, 2005Mark Litchfield of NGSSoftware has discovered a high risk vulnerability in
iTunes which can allow remote code execution through playing a specially
crafted media file, or by visiting a specially crafted web-page.
This issue has been resolved in the latest version of iTunes which can be
obtained from the Apple website:
http://www.apple.com/itunes/download/
NGSSoftware are going to withhold details of this flaw for three months.
Full details will be published on the 10st of August 2005. This three month
window will allow users of Apple iTunes the time needed to apply the patch
before the details are released to the general public. This reflects
NGSSoftware’s approach to responsible disclosure.
NGSSoftware Insight Security Research
http://www.ngssoftware.com
http://www.databasesecurity.com/
+44(0)208 401 0070
