Available for: Microsoft Windows XP and Microsoft Windows 2000
Impact: iTunes 5 for Windows may launch the wrong helper program
Description: Due to the way iTunes 5 for Windows launches its helper
application, multiple system paths are searched to determine which
program to run. This may allow a malicious user on the local system
to create an environment where an alternate program will be executed
by iTunes. This has already been addressed in the iTunes 6 release
for Windows, available from:
http://www.apple.com/itunes/download/
This advisory is being released at this time to coordinate with other
vendors whose products were also affected by their implementation of
the helper application launch mechanism. Credit to iDEFENSE for
reporting this issue.