KLA11623
Multiple vulnerabilities in Apple iTunes
Updated: 01/17/2020
Detect date
?
11/18/2019
Severity
?
Warning
Description

Multiple vulnerabilities were found in Apple Itunes. Malicious users can exploit these vulnerabilities to gain privileges, execute arbitrary code.

Below is a complete list of vulnerabilities:

  1. Multiple memory corruption vulnerabilities in WebKit can be exploited to execute arbitrary code
  2. Unspecified vulnerability in libexpat can be exploited remotely via specially designed XML-file to obtain sensitive information;
  3. Unspecified vulnerability in CFNetwork Proxies can be exploited to gain privileges;
  4. Use-after-free vulnerability in WebKit can be exploited to execute arbitrary code
Affected products

Apple iTunes earlier than 12.10.3

Solution

Update to the latest version
Download iTunes

Original advisories

HT210793

Impacts
?
ACE 
[?]

PE 
[?]
Related products
Apple iTunes
CVE-IDS
?
CVE-2019-159030.0Unknown
CVE-2019-88440.0Unknown
CVE-2019-88480.0Unknown
CVE-2019-88350.0Unknown
CVE-2019-88460.0Unknown