Itunes 8.1 Update Eliminates Vulnerabilities


Recommended Posts

15 March 2009, 13:11

iTunes 8.1 update eliminates vulnerabilities

Apple's iTunes update 8.1 contains two bug fixes relevant to security. Attackers can remotely exploit vulnerabilities in previous versions to partially paralyse the music program or make it expose user data.

The first problem only affects the Windows version. While processing manipulated messages using the proprietary iTunes protocol DAAP (Digital Audio Access Protocol) to share media across a local network, the program may go into an endless loop resulting in a denial of service.

The second bug, in both the Windows and the Mac OS X version, can occur when internet radio broadcasts or podcasts are accessed. Apple says that if a manipulated podcast server is contacted, a successful attack will cause an authentication dialogue to be displayed, asking for an iTunes user name and password to be entered. Any information given in response though, will be accessed by the attacker, enabling them to make guesses about the victim's other passwords. iTunes 8.1 has been modified to correctly identify the source of the prompt message.

If they haven't already done so, iTunes users should install the new version as quickly as possible, either using the update function in Mac OS X or Windows, or by downloading the full updated package.

See also:

About the security content of iTunes 8.1, advisory from Apple.

Heise security - http://www.h-online.com/security/iTunes-8-...s--/news/112851

Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...