Attack (Attack ID:319490)

Release Date2010/03/09

Attack NameEXPLOIT Apple iTunes Protocol Handler Stack Buffer Overflow -3 (CVE-2009-0950)

Severity

BUG ID

CVE ID

 

Description

Stack-based buffer overflow in Apple iTunes before 8.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an itms: URL with a long URL component after a colon.
Impact:Remote code execution
Affected System:Windows, Mac OS
Additional References:BID:35157; CVE-2009-0950

 

Solution

Update vendor's patch.