iTunes 7.4 is now available and addresses the following security
issue:
CVE-ID: CVE-2007-3752
Available for: Mac OS X v10.3.9, Mac OS X v10.4.7 or later,
Windows XP /Vista
Impact: Opening a maliciously crafted music file may lead to an
unexpected application termination or arbitrary code execution
Description: A buffer overflow exists in iTunes when processing
album cover art. By enticing a user to open a maliciously crafted
music file, an attacker may trigger the overflow which may lead to an
unexpected application termination or arbitrary code execution. This
update addresses the issue by performing proper bounds checking.
Credit to David Thiel of iSEC Partners for reporting this issue.
_______________________________________________
Do not post admin requests to the list. They will be ignored.
Security-announce mailing list (email@hidden)
Help/Unsubscribe/Update your Subscription:
This email sent to email@hidden