iTunes < 9.1 Multiple Vulnerabilities (uncredentialed check)

This script is Copyright (C) 2010-2014 Tenable Network Security, Inc.


Synopsis :

The remote host contains a multimedia application that has multiple
vulnerabilities.

Description :

The version of iTunes on the remote host is prior to version 9.1. It
is, therefore, affected by multiple vulnerabilities :

- A buffer underflow in ImageIO's handling of TIFF images
can lead to a denial of service or arbitrary code
execution. (CVE-2009-2285)

- An integer overflow in the application's handling of
images with an embedded color profile can lead to a
denial of service or arbitrary code execution.
(CVE-2010-0040)

- An uninitialized memory access vulnerability in
ImageIO's handling of BMP images can result in the
sending of sensitive data from Safari's memory to
a website under an attacker's control. (CVE-2010-0041)

- An uninitialized memory access vulnerability in
ImageIO's handling of TIFF images can result in the
sending of sensitive data from Safari's memory to
a website under an attacker's control. (CVE-2010-0042)

- A memory corruption vulnerability in the ImageIO's
handling of TIFF images can lead to a denial of
service or arbitrary code execution. (CVE-2010-0043)

- An infinite loop vulnerability in the application's
handling of imported MP4 podcast files can lead to a
denial of service or arbitrary code execution.
(CVE-2010-0531)

- A race condition during the installation process
allows a local attacker to modify an unspecified file
which can then be executed with SYSTEM privileges.
(CVE-2010-0532)

- A path searching vulnerability exists that allows code
execution if an attacker places a specially crafted DLL
in a directory and has a user open another file using
iTunes in that directory. (CVE-2010-1795)

- Syncing a mobile device can allow a local attacker to
gain the privileges of the console user due to an
insecure file operation in the handling of log files.
(CVE-2010-1768)

See also :

http://support.apple.com/kb/HT4105
http://lists.apple.com/archives/security-announce/2010/Mar/msg00003.html
http://www.securityfocus.com/advisories/19388

Solution :

Upgrade to iTunes 9.1 or later.

Risk factor :

High / CVSS Base Score : 9.3
(CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS Temporal Score : 7.7
(CVSS2#E:F/RL:OF/RC:C)
Public Exploit Available : true

Family: Peer-To-Peer File Sharing

Nessus Plugin ID: 45391 (itunes_9_1_banner.nasl)

Bugtraq ID: 38673
38674
38676
38677
39092
39113
42538
42541

CVE ID: CVE-2009-2285
CVE-2010-0040
CVE-2010-0041
CVE-2010-0042
CVE-2010-0043
CVE-2010-0531
CVE-2010-0532
CVE-2010-1768
CVE-2010-1795