KLA12156
Multiple vulnerabilities in Apple iTunes

Обновлено: 11/05/2021
Дата обнаружения
22/04/2021
Уровень угрозы
Warning
Описание

Multiple vulnerabilities were found in Apple iTunes. Malicious users can exploit these vulnerabilities to perform cross-site scripting attack, obtain sensitive information.

Below is a complete list of vulnerabilities:

  1. A cross-site-scripting (XSS) vulnerability in WebKit can be exploited to perform cross-site scripting attack.
  2. A memory initialization vulnerability in CFNetwork can be exploited to obtain sensitive information.
  3. A use after free vulnerability in WebRTC can be exploited to cause denial of service or execute arbitrary code.
  4. An information disclosure vulnerability in CoreText can be exploited to obtain sensitive information.
Пораженные продукты

Apple iTunes earlier than 12.11.3

Решение

Update to the latest version
Download iTunes

Первичный источник обнаружения
About the security content of iTunes 12.11.3 for Windows
Оказываемое влияние
?
OSI 
[?]

XSS/CSS 
[?]
Связанные продукты
Apple iTunes
CVE-IDS
CVE-2021-18110.0Unknown
CVE-2021-18570.0Unknown
CVE-2021-18250.0Unknown
CVE-2020-74634.9Warning
Узнай статистику распространения уязвимостей в твоем регионе