Kaspersky ID:
KLA10877
Дата обнаружения:
25/09/2016
Обновлено:
22/01/2024

Описание

Multiple serious vulnerabilities have been found in Apple iTunes. Malicious users can exploit these vulnerabilities to cause denial of service, execute arbitrary code, bypass security restrictions or obtain sensitive information.

Below is a complete list of vulnerabilities

  1. Multiple unknown vulnerabilities can be exploited remotely via a specially designed content to cause denial of service or execute arbitrary code;
  2. Improper certificates verification can be exploited remotely via a specially designed certificate to obtain sensitive information;
  3. An unknown vulnerability can be exploited remotely via HTTP sessions manipulations to bypass security restrictions;
  4. Lack of restrictions can be exploited remotely via a specially designed content to obtain sensitive information.

Technical details

Vulnerability (2) related to improper verification of X.509 certificate.

Vulnerability (3) can be exploited by conducting DNS rebinding attack via leveraging HTTP/0.9 support.

Vulnerability (4) related to lack of restriction on location variable.

Первичный источник обнаружения

Связанные продукты

Список CVE

  • CVE-2016-4769
    high
  • CVE-2016-4768
    high
  • CVE-2016-4767
    high
  • CVE-2016-4766
    high
  • CVE-2016-4765
    high
  • CVE-2016-4763
    warning
  • CVE-2016-4762
    high
  • CVE-2016-4760
    warning
  • CVE-2016-4759
    high
  • CVE-2016-4758
    warning

Смотрите также

Узнай статистику распространения уязвимостей в своем регионе statistics.securelist.com

Нашли неточность в описании этой уязвимости? Дайте нам знать!
Kaspersky IT Security Calculator:
Оцените ваш профиль кибербезопасности
Узнать больше
Встречай новый Kaspersky!
Каждая минута твоей онлайн-жизни заслуживает топовой защиты.
Узнать больше
Confirm changes?
Your message has been sent successfully.