Apple iTunes
The latest vulnerability lies in the cover art display system used by iTunes
R E L A T E D   C O N T E N T

Free email newsletters




ADVERTISEMENT

Apple slips security fix into iTunes update

Software exposes users to remote code execution vulnerability

Shaun Nichols in California, vnunet.com 07 Sep 2007
ADVERTISEMENT

Apple has included a fix for a remote code execution vulnerability for the OS X and Windows versions of its latest iTunes 7.4 release.

The software was unveiled on 5 September to support a new range of iPods and a ring-tone builder.

The vulnerability lies in the cover art display system used by iTunes. Cover art is displayed while a track is playing, but is also used to navigate music in the Cover Flow interface.

By creating a specially malformed file, an attacker could cause an application crash or execute arbitrary code.

Remote code execution flaws are considered to be the most serious type of vulnerability, because they can be used by attackers to install malware.

Apple credited David Thiel, a security researcher at iSec Partners, with discovering the vulnerability.

Security firm Secunia rated the flaw as 'highly critical', the second highest of its alert levels. Secunia and the US Computer Emergency Readiness Team recommended that users install the update as soon as possible.

ITunes has yet to fall victim to a major attack, but other Apple products have been targeted by malware authors.

Late last year a piece of malware spread through MySpace preying on users via a flaw in Apple's QuickTime software.

The infamous MPack exploit tool has also been known to target Quicktime vulnerabilities.

See also:

Apple iPod TouchMedia player gains Wi-Fi and touch screen  06 Sep 2007
Studio cuts new deal just days after dumping iTunes  05 Sep 2007
Apple rings the changes  04 Sep 2007
Apple iPhoneAll the latest news on Apple's iPhone  18 Dec 2007

All Bugs & Fixes

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
Reading, Berkshire, United Kingdom | EDS
Position # 395423 Environment Manager Location - Reading, Berkshire Job Description: There is a requirement for an Environmental Manager for the Sandpits environment. This position is to act as the single point of contact for ... more >
Reading, Berkshire, United Kingdom | EDS
Job Description: A skilled System Integrator to integrate application hosting environments to support business requirements. The Candidate will possess specific experience of enterprise systems, component validation and integrating technical Infrastructures and system management facilities within ... more >
(Poole, Bournemouth, Dorset, Hampshire), United Kingdom | RNLI
Analyst - Network & Telecoms - £35,000+ - Poole, Bournemouth, Dorset, Hampshire Our data and voice network team's impact on the organisation is considerable. And with something in the region of 5,000 direct users connected ... more >
Central London, United Kingdom | MI5 Security Services
Windows Technician - Competitive salaries + excellent benefits - Central London Getting the best out of technology is critical to helping us protect the UK. Join MI5 and use your skills and experience to help us ... more >
More job opportunities