Apple iTunes < 9.1 Multiple Vulnerabilities (uncredentialed check)

High Nessus Plugin ID 45391

Synopsis

The remote host contains a multimedia application that has multiple vulnerabilities.

Description

The version of Apple iTunes on the remote host is prior to version 9.1. It is, therefore, affected by multiple vulnerabilities :

- A buffer underflow in ImageIO's handling of TIFF images can lead to a denial of service or arbitrary code execution. (CVE-2009-2285)

- An integer overflow in the application's handling of images with an embedded color profile can lead to a denial of service or arbitrary code execution.
(CVE-2010-0040)

- An uninitialized memory access vulnerability in ImageIO's handling of BMP images can result in the sending of sensitive data from Safari's memory to a website under an attacker's control. (CVE-2010-0041)

- An uninitialized memory access vulnerability in ImageIO's handling of TIFF images can result in the sending of sensitive data from Safari's memory to a website under an attacker's control. (CVE-2010-0042)

- A memory corruption vulnerability in the ImageIO's handling of TIFF images can lead to a denial of service or arbitrary code execution. (CVE-2010-0043)

- An infinite loop vulnerability in the application's handling of imported MP4 podcast files can lead to a denial of service or arbitrary code execution.
(CVE-2010-0531)

- A race condition during the installation process allows a local attacker to modify an unspecified file which can then be executed with SYSTEM privileges.
(CVE-2010-0532)

- A path searching vulnerability exists that allows code execution if an attacker places a specially crafted DLL in a directory and has a user open another file using iTunes in that directory. (CVE-2010-1795)

- Syncing a mobile device can allow a local attacker to gain the privileges of the console user due to an insecure file operation in the handling of log files.
(CVE-2010-1768)

Solution

Upgrade to Apple iTunes 9.1 or later.

See Also

http://support.apple.com/kb/HT4105

http://lists.apple.com/archives/security-announce/2010/Mar/msg00003.html

http://www.securityfocus.com/advisories/19388

Plugin Details

Severity: High

ID: 45391

File Name: itunes_9_1_banner.nasl

Version: 1.17

Type: remote

Published: 2010/03/31

Modified: 2018/07/12

Dependencies: 20217

Risk Information

Risk Factor: High

CVSSv2

Base Score: 9.3

Temporal Score: 7.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Temporal Vector: CVSS2#E:POC/RL:OF/RC:C

Vulnerability Information

CPE: cpe:/a:apple:itunes

Required KB Items: iTunes/sharing

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2010/03/30

Vulnerability Publication Date: 2010/03/30

Reference Information

CVE: CVE-2009-2285, CVE-2010-0040, CVE-2010-0041, CVE-2010-0042, CVE-2010-0043, CVE-2010-0531, CVE-2010-0532, CVE-2010-1768, CVE-2010-1795

BID: 38673, 38674, 38676, 38677, 39092, 39113, 42538, 42541

CWE: 119