May 12 2005

Apple fixes critical iTunes bug

  • Written by
  • No Comments


      Share

Music fans were this week urged to update their iTunes software following the discovery of a serious security bug that creates a means for hackers to take over vulnerable systems.

A bug in code used by iTunes 4.X to parse MPEG-4 files means that maliciously-crafted media files can crash vulnerable versions of the application. In the process, hostile code can be injected into vulnerable systems. A classic buffer overflow attack. iTunes users are advised to update to version 4.8, which features improved validation checks, to guard against possible exploitation.

Danish security reporting firm Secunia rates the iTunes bug as “highly critical”. Exploitations of both Mac OS and Windows machines running iTunes is possible – providing an attacker tricks a user into opening a malicious MPEG-4 file with a vulnerable version of iTunes.

Related

  1. Firefox 1.5.0.5 update plugs ‘critical’ holes
  2. uTorrent “Highly Critical” Vulnerability Discovered
  3. Kazaa security hole undermines network
  4. ‘Highly critical’ Linux flaw patches
  5. Apple disables iTunes hack
Zeropaid on Facebook

Trackbacks url:

Leave a Comment...



  • Advertisement

    Giganews Newsgroups


  • Jared Moya: done......
  • mafia_hitman: tanks me to i need an invitation please my e-mail nativedeen1991@gmail.com...
  • RooF: change the picture of the article because it isnt what you think it is. It shows the former prime minister (ΝΔ is the ...
  • ra: SHA1 hash is the key...
  • Mike: I have been a member of Demonoid for over 3 years. To this day I have NEVER invited a single person...and you ppl think ...
  • aaron: sorry that should read 3,000 albums, hehe!...
  • aaron: I think soulseek is number 1! I have managed to download over 30,000 albums using this site! Allways good quality and m...
  • geo: va rog eu imi dati si mie o invitatie tot pe torrentbits.ro:D hai va rog mult.. marius_ema12@yahoo.com...
  • sdsd