iTunes < 9.1 Multiple Vulnerabilities (uncredentialed check)

This script is Copyright (C) 2010-2012 Tenable Network Security, Inc.


Synopsis :

The remote host contains an application that is affected by multiple
vulnerabilities.

Description :

The remote version of iTunes is older than 9.1. Such versions may be
affected by multiple vulnerabilities :

- A buffer underflow in ImageIO's handling of TIFF images
may lead to an application crash or arbitrary code
execution. (CVE-2009-2285)

- An integer overflow in the applications's handling of
images with an embedded color profile may lead to an
application crash or arbitrary code execution.
(CVE-2010-0040)

- An uninitialized memory access issue in ImageIO's
handling of BMP images may result in sending data from
Safari's memory to a website under an attacker's
control. (CVE-2010-0041)

- An uninitialized memory access issue in ImageIO's
handling of TIFF images may result in sending data from
Safari's memory to a website under an attacker's
control. (CVE-2010-0042)

- A memory corruption issue in the application's handling
of TIFF images may lead to an application crash or
arbitrary code execution. (CVE-2010-0043)

- An infinite loop in the application's handling of
imported MP4 podcast files may lead to an application
crash and prevent subsequent operation. (CVE-2010-0531)

- A race condition during the installation process may
allow a local user to modify a file that is then
executed with SYSTEM privileges. (CVE-2010-0532)

- A path searching issue may allow code execution if an
attacker can place a specially crafted DLL in a
directory and have a user open another file using
iTunes in that directory. (CVE-2010-1795)

- Syncing a mobile device may allow a local user to gain
the privileges of the console user due to an insecure
file operation in the handling of log files.
(CVE-2010-1768)

See also :

http://support.apple.com/kb/HT4105
http://lists.apple.com/archives/security-announce/2010/Mar/msg00003.html
http://www.securityfocus.com/advisories/19388

Solution :

Upgrade to iTunes 9.1 or later.

Risk factor :

High / CVSS Base Score : 9.3
(CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS Temporal Score : 7.7
(CVSS2#E:F/RL:OF/RC:C)
Public Exploit Available : true

Family: Peer-To-Peer File Sharing

Nessus Plugin ID: 45391 (itunes_9_1_banner.nasl)

Bugtraq ID: 38673
38674
38676
38677
39092
39113
42538
42541

CVE ID: CVE-2009-2285
CVE-2010-0040
CVE-2010-0041
CVE-2010-0042
CVE-2010-0043
CVE-2010-0531
CVE-2010-0532
CVE-2010-1768
CVE-2010-1795