Software exposes users to remote code execution vulnerability
Shaun Nichols in California, vnunet.com07 Sep 2007
ADVERTISEMENT
Apple has
included a fix for a remote code execution vulnerability for the OS X and
Windows versions of its latest
iTunes
7.4 release.
The software was unveiled on 5 September to support a
new range of iPods
and a ring-tone builder.
The vulnerability lies in the cover art display system used by iTunes. Cover
art is displayed while a track is playing, but is also used to navigate music in
the Cover Flow interface.
By creating a specially malformed file, an attacker could cause an
application crash or execute arbitrary code.
Remote code execution flaws are considered to be the most serious type of
vulnerability, because they can be used by attackers to install malware.
Apple credited David Thiel, a security researcher at
iSec
Partners, with discovering the vulnerability.
Security firm
Secunia
rated the flaw as 'highly critical', the second highest of its alert levels.
Secunia and the
US
Computer Emergency Readiness Team recommended that users install the update
as soon as possible.
ITunes has yet to fall victim to a major attack, but other Apple products
have been targeted by malware authors.
Java, J2EE, Developer, Spring, Hibernate, London, city, Graduate. This is an amazing opportunity to join a successful city based team working at the cutting edge of development. My client is looking for strong Java/J2EE developers ... more >
E-Commerce, Greenfield, Agile, Java, J2EE, , JavaScript, SQL, London, City Graduate This is an exceptional opportunity for a talented Java, J2EE developer keen to work in a successful development team within arguable the best agile ... more >
2nd Line Support Analyst London £35, 000 to £40, 500 My client is a global market leader in the Internet Applications Industry. The company is continually progressing and looking for areas of growth and this ... more >
Security Architect / Information Security Specialist – St Albans - Global Leader - Shine At The Highest Level Security Solution Architect / Information Security Architect required by renowned blue-chip organisation offering the finest security projects ... more >More job opportunities