May 12 2005

Apple fixes critical iTunes bug

  • Written by moneoa
  • No Comments

Music fans were this week urged to update their iTunes software following the discovery of a serious security bug that creates a means for hackers to take over vulnerable systems.

A bug in code used by iTunes 4.X to parse MPEG-4 files means that maliciously-crafted media files can crash vulnerable versions of the application. In the process, hostile code can be injected into vulnerable systems. A classic buffer overflow attack. iTunes users are advised to update to version 4.8, which features improved validation checks, to guard against possible exploitation.

Danish security reporting firm Secunia rates the iTunes bug as “highly critical”. Exploitations of both Mac OS and Windows machines running iTunes is possible – providing an attacker tricks a user into opening a malicious MPEG-4 file with a vulnerable version of iTunes.

Related Posts

  1. Firefox 1.5.0.5 update plugs ‘critical’ holes
  2. uTorrent “Highly Critical” Vulnerability Discovered
  3. Kazaa security hole undermines network
  4. ‘Highly critical’ Linux flaw patches
  5. Apple disables iTunes hack
Zeropaid on Facebook
Trackbacks url:

Leave a Comment...

  • Advertisement

    Giganews Newsgroups

1 Star2 Stars3 Stars4 Stars5 Stars Loading ... Loading ...

  • Sophieanne and Lilli: I wish their was more music....
  • ralphie: OH looky, it still doesn't work on dual screens. Adobe sucks....
  • odball: hej jag är en leged user och nu kommer jag inte in på sidan kan ni vara snälla och undersöka varför mvh G.P...
  • mpsharp.com Blog » Watching NFL games online: [...] show you a number of streams to choose from for each game.  All the streams require some sort of StreamTorrent pl...
  • ejonesss: no it is not going to completely stop piracy because while it will stop those whose reason for piracy is quality it is n...
  • file sharing anonymously - P2Pfreak.com: [...] and Trusty Files) just google any one of them and you will get some great info. also here IP filtering with uTorr...
  • soulxtc: Wasn't aware people were guaranteed jobs...
  • mountain_rage: BTW Youtube is supposed to go 1080P soon :D....
  • sdsd