Apple iTunes '.pls' File Buffer Overflow Vulnerability
BID:36478
Info
Apple iTunes '.pls' File Buffer Overflow Vulnerability
| Bugtraq ID: | 36478 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2009-2817 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 22 2009 12:00AM |
| Updated: | Feb 17 2010 08:32PM |
| Credit: | Roger Hart of IP3, and Steven Woolley at Oogli LLC |
| Vulnerable: |
eSignal eSignal 6.0.2 Apple iTunes 9.0 Apple iTunes 7.3.2 Apple iTunes 7.3.1 Apple iTunes 7.3 Apple iTunes 7.0.2 Apple iTunes 6.0.5 Apple iTunes 6.0.4 Apple iTunes 6.0.3 Apple iTunes 6.0.1 Apple iTunes 6.0 Apple iTunes 5.0 Apple iTunes 4.8 Apple iTunes 4.7.1 Apple iTunes 4.7 Apple iTunes 4.6 Apple iTunes 4.5 Apple iTunes 4.2 .72 Apple iTunes 8.2 Apple iTunes 8.1 Apple iTunes 8.0 Apple iTunes 7.4 |
| Not Vulnerable: |
Apple iTunes 9.0.1 |
Discussion
Apple iTunes '.pls' File Buffer Overflow Vulnerability
Apple iTunes is prone to a buffer-overflow vulnerability because the software fails to bounds-check user-supplied data before copying it into an insufficiently sized buffer.
An attacker can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
Versions prior to Apple iTunes 9.0.1 are vulnerable.
Apple iTunes is prone to a buffer-overflow vulnerability because the software fails to bounds-check user-supplied data before copying it into an insufficiently sized buffer.
An attacker can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
Versions prior to Apple iTunes 9.0.1 are vulnerable.
Exploit / POC
Apple iTunes '.pls' File Buffer Overflow Vulnerability
A commercial exploit is available for CORE IMPACT. This exploit is not otherwise known to be public or circulating in the wild.
A commercial proof of concept is available through VUPEN Security - Exploit and PoC Service. This proof of concept is not otherwise publicly available or known to be circulating in the wild.
The following exploit is available:
A commercial exploit is available for CORE IMPACT. This exploit is not otherwise known to be public or circulating in the wild.
A commercial proof of concept is available through VUPEN Security - Exploit and PoC Service. This proof of concept is not otherwise publicly available or known to be circulating in the wild.
The following exploit is available:
Solution / Fix
Apple iTunes '.pls' File Buffer Overflow Vulnerability
Solution:
Vendor updates are available. Please see the referenced advisory for details.
Apple iTunes 8.0
Apple iTunes 8.2
Apple iTunes 8.1
Apple iTunes 9.0
Solution:
Vendor updates are available. Please see the referenced advisory for details.
Apple iTunes 8.0
-
Apple APPLE-SA-2009-09-22-1-iTunes64Setup.exe
http://www.apple.com/itunes/download/ -
Apple APPLE-SA-2009-09-22-1-iTunesSetup.exe
http://www.apple.com/itunes/download/ -
Apple iTunes9.0.1.dmg
http://www.apple.com/itunes/download/
Apple iTunes 8.2
-
Apple APPLE-SA-2009-09-22-1-iTunes64Setup.exe
http://www.apple.com/itunes/download/ -
Apple APPLE-SA-2009-09-22-1-iTunesSetup.exe
http://www.apple.com/itunes/download/ -
Apple iTunes9.0.1.dmg
http://www.apple.com/itunes/download/
Apple iTunes 8.1
-
Apple APPLE-SA-2009-09-22-1-iTunes64Setup.exe
http://www.apple.com/itunes/download/ -
Apple APPLE-SA-2009-09-22-1-iTunesSetup.exe
http://www.apple.com/itunes/download/ -
Apple iTunes9.0.1.dmg
http://www.apple.com/itunes/download/
Apple iTunes 9.0
-
Apple APPLE-SA-2009-09-22-1-iTunes64Setup.exe
http://www.apple.com/itunes/download/ -
Apple APPLE-SA-2009-09-22-1-iTunesSetup.exe
http://www.apple.com/itunes/download/ -
Apple iTunes9.0.1.dmg
http://www.apple.com/itunes/download/