KLA11602
Multiple vulnerabilities in Apple iTunes
Обновлено: 15/11/2019
Дата обнаружения
30/10/2019
Уровень угрозы
Critical
Описание

Multiple vulnerabilities were found in Apple iTunes. Malicious users can exploit these vulnerabilities to execute arbitrary code, perform cross-site scripting attack.

Below is a complete list of vulnerabilities:

  1. Multiple memory corruption vulnerabilities in WebKit Process Model can be exploited to execute arbitrary code;
  2. Multiple memory corruption vulnerabilities in WebKit can be exploited to execute arbitrary code;
  3. A logic vulnerability in WebKit can be exploited to perform cross-site scripting attacks;
  4. A dynamic library loading vulnerability in iTunes can be exploited to execute arbitrary code;
  5. A memory corruption vulnerability in Graphics Driver can be exploited to execute arbitrary code;
Пораженные продукты

Apple iTunes earlier than 12.10.2

Решение

Update to the latest version
Download iTunes

Первичный источник обнаружения
HT210726
Оказываемое влияние
?
ACE 
[?]

XSS/CSS 
[?]
Связанные продукты
Apple iTunes
CVE-IDS
CVE-2019-88150.0Unknown
CVE-2019-87820.0Unknown
CVE-2019-88220.0Unknown
CVE-2019-88230.0Unknown
CVE-2019-88080.0Unknown
CVE-2019-87830.0Unknown
CVE-2019-88110.0Unknown
CVE-2019-88130.0Unknown
CVE-2019-88120.0Unknown
CVE-2019-88140.0Unknown
CVE-2019-88190.0Unknown
CVE-2019-88160.0Unknown
CVE-2019-88010.0Unknown
CVE-2019-87840.0Unknown
CVE-2019-88200.0Unknown
CVE-2019-88210.0Unknown