KLA11592
Multiple vulnerabilities in Apple iTunes

Updated: 06/03/2020
Detect date
?
10/07/2019
Severity
?
Warning
Description

Multiple vulnerabilities were found in Apple iTunes. Malicious users can exploit these vulnerabilities to execute arbitrary code, perform cross-site scripting attack, cause denial of service.

Below is a complete list of vulnerabilities:

  1. Vulnerabilitiy in WebKit can be exploited remotely via specially crafted text file to execute arbitrary code;
  2. Vulnerabilitiy in WebKit can be exploited remotely via specially crafted web content to perform cross-site scripting attacks;
  3. Vulnerabilitiy in UIFoundation can be exploited remotely via specially crafted text file to execute arbitrary code;
  4. Vulnerabilitiy in CoreCrypto can be exploited remotely to cause denial of service;
  5. Vulnerabilitiy in CoreMedia can be exploited remotely via specially crafted web content to execute arbitrary code;
  6. Vulnerabilitiy in Foundation can be exploited remotely to execute arbitrary code;
  7. A memory corruption vulnerability in libxml2 can be exploited remotely to execute arbitrary code;
  8. A memory corruption vulnerability in libxslt can be exploited remotely to execute arbitrary code;
Affected products

Apple iTunes earlier than 12.10.1

Solution

Update to latest version
Download iTunes

Original advisories

HT210635

Impacts
?
ACE 
[?]

DoS 
[?]

XSS/CSS 
[?]
Related products
Apple iTunes
CVE-IDS
?
Find out the statistics of the vulnerabilities spreading in your region