iTunes < 9.2 Multiple Vulnerabilities (uncredentialed check)

This script is Copyright (C) 2010-2014 Tenable Network Security, Inc.


Synopsis :

The remote host contains a multimedia application that has multiple
vulnerabilities.

Description :

The version of iTunes on the remote host is prior to version 9.2. It
is, therefore, affected by multiple vulnerabilities :

- A heap-based buffer overflow vulnerability exists in the
handling of images with an embedded ColorSync profile.
By using a specially crafted image, a remote attacker
can exploit this to cause a denial of service or execute
arbitrary code. (CVE-2009-1726)

- Multiple integer overflow vulnerabilities exist in
ImageIO's handling of TIFF files. By using a specially
crafted TIFF file, a remote attacker can exploit these
to cause a denial of service or execute arbitrary code.
(CVE-2010-1411)

- The WebKit component contains multiple vulnerabilities
that can be exploited, including the execution of
arbitrary code.
(CVE-2010-0544, CVE-2010-1119, CVE-2010-1387,
CVE-2010-1390, CVE-2010-1392, CVE-2010-1393,
CVE-2010-1395, CVE-2010-1396, CVE-2010-1397,
CVE-2010-1398, CVE-2010-1399, CVE-2010-1400,
CVE-2010-1401, CVE-2010-1402, CVE-2010-1403,
CVE-2010-1404, CVE-2010-1405, CVE-2010-1408,
CVE-2010-1409, CVE-2010-1410, CVE-2010-1412,
CVE-2010-1414, CVE-2010-1415, CVE-2010-1416,
CVE-2010-1417, CVE-2010-1418, CVE-2010-1419,
CVE-2010-1421, CVE-2010-1422, CVE-2010-1749,
CVE-2010-1758, CVE-2010-1759, CVE-2010-1761,
CVE-2010-1763, CVE-2010-1769, CVE-2010-1770,
CVE-2010-1771, CVE-2010-1774)

See also :

http://support.apple.com/kb/HT4220
http://lists.apple.com/archives/security-announce/2010/Jun/msg00002.html

Solution :

Upgrade to iTunes 9.2 or later.

Risk factor :

High / CVSS Base Score : 9.3
(CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS Temporal Score : 6.9
(CVSS2#E:U/RL:OF/RC:C)
Public Exploit Available : false