Apple iTunes < 10.6.3 Multiple Vulnerabilities (credentialed check)

High Nessus Plugin ID 59497


The remote host contains a multimedia application that has multiple vulnerabilities.


The version of Apple iTunes installed on the remote Windows host is older than 10.6.3 and is, therefore, affected by the following issues :

- A memory corruption issue exists in WebKit that can allow malicious websites to crash the application and possibly to execute arbitrary code. (CVE-2012-0672)

- Stack and heap based buffer overflow errors related to the handling of 'm3u' playlist files. These errors can cause the application to crash or possibly allow arbitrary code execution. (CVE-2012-0677)


Upgrade to Apple iTunes 10.6.3 or later.

See Also

Plugin Details

Severity: High

ID: 59497

File Name: itunes_10_6_3.nasl

Version: $Revision: 1.12 $

Type: local

Agent: windows

Family: Windows

Published: 2012/06/14

Modified: 2016/11/23

Dependencies: 25996

Risk Information

Risk Factor: High


Base Score: 9.3

Temporal Score: 7.7

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Temporal Vector: CVSS2#E:F/RL:OF/RC:ND

Vulnerability Information

CPE: cpe:/a:apple:itunes

Required KB Items: SMB/iTunes/Version

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2012/06/11

Vulnerability Publication Date: 2012/06/11

Exploitable With


Core Impact

Metasploit (Apple iTunes 10 Extended M3U Stack Buffer Overflow)

Reference Information

CVE: CVE-2012-0672, CVE-2012-0677

BID: 53404, 53933, 54113

OSVDB: 81792, 82897, 83220

EDB-ID: 19098, 19322, 19387