Summary
This host is installed with Apple iTunes and is prone to remote code execution vulnerability.
Impact
Successful exploitation could allow attackers to execute arbitrary code in the context of the user running the affected application.
Impact Level: Application
Solution
Upgrade to Apple Apple iTunes version 10.5.1 or later, For updates refer to http://www.apple.com/itunes/download/
Insight
The flaw is due to the improper verification of authenticity of updates, allows man-in-the-middle attack execute arbitrary code via a Trojan horse update.
Affected
Apple iTunes version prior to 10.5.1 (10.5.1.42) on Windows
References
Severity
Classification
-
CVE CVE-2008-3434 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities
- 7T Interactive Graphical SCADA System Multiple Security Vulnerabilities
- Adobe Extension Manager CS5 Insecure Library Loading Vulnerability (Win)
- Adobe Flash Player Buffer Overflow Vulnerability - Apr14 (Windows)
- Adobe Acrobat Remote Code Execution Vulnerability(Win)
- Adobe Flash Player Buffer Overflow Vulnerability - Apr14 (Mac OS X)