Please fill in the field below to receive your profile link.
ADVERTISEMENT
Apple slips security fix into iTunes update
Software exposes users to remote code execution vulnerability
Shaun Nichols in California, vnunet.com07 Sep 2007
ADVERTISEMENT
Apple has
included a fix for a remote code execution vulnerability for the OS X and
Windows versions of its latest
iTunes
7.4 release.
The software was unveiled on 5 September to support a
new range of iPods
and a ring-tone builder.
The vulnerability lies in the cover art display system used by iTunes. Cover
art is displayed while a track is playing, but is also used to navigate music in
the Cover Flow interface.
By creating a specially malformed file, an attacker could cause an
application crash or execute arbitrary code.
Remote code execution flaws are considered to be the most serious type of
vulnerability, because they can be used by attackers to install malware.
Apple credited David Thiel, a security researcher at
iSec
Partners, with discovering the vulnerability.
Security firm
Secunia
rated the flaw as 'highly critical', the second highest of its alert levels.
Secunia and the
US
Computer Emergency Readiness Team recommended that users install the update
as soon as possible.
ITunes has yet to fall victim to a major attack, but other Apple products
have been targeted by malware authors.
Position # 395423 Environment Manager Location - Reading, Berkshire Job Description: There is a requirement for an Environmental Manager for the Sandpits environment. This position is to act as the single point of contact for ... more >
Job Description: A skilled System Integrator to integrate application hosting environments to support business requirements. The Candidate will possess specific experience of enterprise systems, component validation and integrating technical Infrastructures and system management facilities within ... more >
(Poole, Bournemouth, Dorset, Hampshire), United Kingdom | RNLI
Analyst - Network & Telecoms - £35,000+ - Poole, Bournemouth, Dorset, Hampshire Our data and voice network team's impact on the organisation is considerable. And with something in the region of 5,000 direct users connected ... more >
Central London, United Kingdom | MI5 Security Services
Windows Technician - Competitive salaries + excellent benefits - Central London Getting the best out of technology is critical to helping us protect the UK. Join MI5 and use your skills and experience to help us ... more >More job opportunities