Apple iTunes DLL Loading Arbitrary Code Execution Vulnerability
BID:42541
Info
Apple iTunes DLL Loading Arbitrary Code Execution Vulnerability
| Bugtraq ID: | 42541 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2010-1795 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Aug 12 2010 12:00AM |
| Updated: | Mar 19 2015 09:44AM |
| Credit: | Simon Raner of ACROS Security |
| Vulnerable: |
Apple iTunes 9.0.2 Apple iTunes 9.0.1 .8 Apple iTunes 9.0.1 Apple iTunes 9.0 Apple iTunes 7.3.2 Apple iTunes 7.3.1 Apple iTunes 7.3 Apple iTunes 8.2 Apple iTunes 8.1 Apple iTunes 8.0.2.20 Apple iTunes 8.0 Apple iTunes 7.4 |
| Not Vulnerable: |
Apple iTunes 9.1 |
Discussion
Apple iTunes DLL Loading Arbitrary Code Execution Vulnerability
Apple iTunes is prone to a vulnerability that lets attackers execute arbitrary code.
An attacker can exploit this issue by enticing a legitimate user into using iTunes to open a media file from a network share location that contains a specially crafted Dynamic Linked Library (DLL) file.
This issue affects iTunes 9 running on Microsoft Windows platforms.
Apple iTunes is prone to a vulnerability that lets attackers execute arbitrary code.
An attacker can exploit this issue by enticing a legitimate user into using iTunes to open a media file from a network share location that contains a specially crafted Dynamic Linked Library (DLL) file.
This issue affects iTunes 9 running on Microsoft Windows platforms.
Exploit / POC
Apple iTunes DLL Loading Arbitrary Code Execution Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Apple iTunes DLL Loading Arbitrary Code Execution Vulnerability
Solution:
Vendor fixes are available. Please see the references for more information.
Solution:
Vendor fixes are available. Please see the references for more information.
References
Apple iTunes DLL Loading Arbitrary Code Execution Vulnerability
References:
References:
- About the security content of iTunes 9.1 (Apple)
- ASPR #2010-08-18-1: Remote Binary Planting in Apple iTunes for Windows (Simon Raner of ACROS Security)
- iTunes Homepage (Apple)