Thursday, September 6, 2007

Apple iTunes Music File Buffer Overflow Vulnerability

A vulnerability has been reported in Apple iTunes, which can be exploited by malicious people to compromise a user's system.

The vulnerability is caused due to an unspecified boundary error when processing album cover art. This can be exploited to cause a buffer overflow via a specially crafted music file.

Successful exploitation may allow execution of arbitrary code.

The vulnerability is reported in versions prior to 7.4.

The vendor credits David Thiel, iSEC Partners

No comments:

Post a Comment