Skip to main content

Apple iTunes WebKit Multiple Vulnerabilities

Last Update Date: 21 Apr 2011 12:22 Release Date: 21 Apr 2011 5691 Views

RISK: High Risk

TYPE: Clients - Audio & Video

TYPE: Audio & Video

Two vulnerabilities have been identified in Apple iTunes, which could be exploited by remote attackers to compromise a vulnerable system.

  1. Due to a use-after-free error in WebKit when handling text nodes, which could be exploited to execute arbitrary code via a malicious web page.
  2. Due to an integer overflow error in WebKit when handling certain style data, which could be exploited by remote attackers to execute arbitrary code via a specially crafted web page.

Impact

  • Remote Code Execution

System / Technologies affected

  • Apple iTunes versions prior to 10.2.2

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.


Vulnerability Identifier


Source


Related Link