KLA11455
Multiple vulnerabilities in Apple iTunes
Обновлено: 26/06/2019
Дата обнаружения
25/03/2019
Уровень угрозы
Critical
Описание

Multiple vulnerabilities were found in Apple iTunes. Malicious users can exploit these vulnerabilities to execute arbitrary code, perform cross-site scripting attack, obtain sensitive information, bypass security restrictions and gain privileges.

Below is a complete list of vulnerabilities:

  1. A type confusion vulnerability in WebKit can be exploited remotely to execute arbitrary code;
  2. Multiple memory corruption vulnerabilities can be exploited remotely to execute arbitrary code;
  3. Multiple logic vulnerabilities in WebKit can be exploited remotely to perform cross-site scripting attack;
  4. A validation vulnerability in WebKit can be exploited remotely to obtain sensitive information;
  5. A memory corruption vulnerability can be exploited loccaly to bypass security restrictions;
  6. A buffer overflow vulnerability in CoreCrypto can be exploited locally to elevate privileges;
  7. A cross-origin vulnerability in WebKit can be exploited locally to obtain sensitive information;
Пораженные продукты

Apple iTunes earlier than 12.9.4

Решение

Update to the latest version
Download iTunes

Первичный источник обнаружения
HT209604
Оказываемое влияние
?
ACE 
[?]

OSI 
[?]

SB 
[?]

PE 
[?]
Связанные продукты
Apple iTunes
CVE-IDS
CVE-2019-72850.0Unknown
CVE-2019-62010.0Unknown
CVE-2019-85060.0Unknown
CVE-2019-85180.0Unknown
CVE-2019-85630.0Unknown
CVE-2019-85440.0Unknown
CVE-2019-85510.0Unknown
CVE-2019-85350.0Unknown
CVE-2019-85230.0Unknown
CVE-2019-85590.0Unknown
CVE-2019-85580.0Unknown
CVE-2019-85030.0Unknown
CVE-2019-85560.0Unknown
CVE-2019-72920.0Unknown
CVE-2019-85620.0Unknown
CVE-2019-85240.0Unknown
CVE-2019-85360.0Unknown
CVE-2019-85420.0Unknown
CVE-2019-85150.0Unknown