Apple iTunes < 10.6.3 Multiple Vulnerabilities (uncredentialed check)

High Nessus Plugin ID 59498


The remote host contains a multimedia application that has multiple vulnerabilities.


The version of Apple iTunes on the remote Windows host is prior to version 10.6.3. It is, therefore, affected by the following vulnerabilities :

- A memory corruption vulnerability exists in the WebKit component. By using a specially crafted website, an attacker can exploit this to cause a denial of service or execute arbitrary code. Note that this vulnerability was addressed on Mac OS X systems by an update for Safari and, therefore, may not necessarily affect the remote host. (CVE-2012-0672)

- Stack and heap based buffer overflow errors exist in the handling of 'm3u' playlist files. An attacker can exploit these to cause a denial of service or execute arbitrary code. (CVE-2012-0677)


Upgrade to Apple iTunes 10.6.3 or later.

See Also

Plugin Details

Severity: High

ID: 59498

File Name: itunes_10_6_3_banner.nasl

Version: $Revision: 1.14 $

Type: remote

Published: 2012/06/14

Modified: 2016/11/23

Dependencies: 20217

Risk Information

Risk Factor: High


Base Score: 9.3

Temporal Score: 7.7

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Temporal Vector: CVSS2#E:F/RL:OF/RC:ND

Vulnerability Information

CPE: cpe:/a:apple:itunes

Required KB Items: iTunes/sharing

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2012/06/11

Vulnerability Publication Date: 2012/06/11

Exploitable With


Core Impact

Metasploit (Apple iTunes 10 Extended M3U Stack Buffer Overflow)

Reference Information

CVE: CVE-2012-0672, CVE-2012-0677

BID: 53404, 53933, 54113

OSVDB: 81792, 82897, 83220

EDB-ID: 19098, 19322, 19387