SynopsisThe remote host contains a multimedia application that has multiple vulnerabilities.
DescriptionThe version of Apple iTunes on the remote Windows host is prior to version 10.6.3. It is, therefore, affected by the following vulnerabilities :
- A memory corruption vulnerability exists in the WebKit component. By using a specially crafted website, an attacker can exploit this to cause a denial of service or execute arbitrary code. Note that this vulnerability was addressed on Mac OS X systems by an update for Safari and, therefore, may not necessarily affect the remote host. (CVE-2012-0672)
- Stack and heap based buffer overflow errors exist in the handling of 'm3u' playlist files. An attacker can exploit these to cause a denial of service or execute arbitrary code. (CVE-2012-0677)
SolutionUpgrade to Apple iTunes 10.6.3 or later.