On mySimon: Holiday Gifts for Mom and Dad
BNET Business Network:
BNET
TechRepublic
ZDNet

September 6th, 2007

Apple plugs gaping iTunes hole, doesn't tell everyone

Posted by Ryan Naraine @ 9:20 am

Categories: Apple, Botnets, Browsers, Data theft, Digital rights management, Exploit code, Hackers, Metasploit, Passwords, Patch Watch, Pen testing, Responsible disclosure, Spam and Phishing, Spyware and Adware, Viruses and Worms, Vulnerability research, Zero-day attacks

Tags: Security, Apple Macintosh, Apple Inc., Buffer-overflow, Apple iTunes, Ryan Naraine

Apple today shipped an iTunes software refresh to add support for all its shiny new toys but, unless you’re following security announcements closely, you’d never know that iTunes 7.4 contains a fix for a pretty nasty code execution vulnerability.

Here’s what Mac users see:

Apple plugs gaping iTunes hole, doesn’t tell anyone

No mention whatsoever of CVE-2007-3752, a buffer overflow vulnerability that puts both Mac and Windows users at risk of arbitrary code execution attacks.

Our own Apple bloggers completely missed the security component of this iTunes update.

To be fair, the company did issue a brief advisory with basic details of this patch but, unless you pay close attention to these things, you just might skip this update because there’s no prominent security warning from Apple.

Here’s Apple’s own explanation of the impact of this flaw, which was reported by David Thiel of iSEC Partners:

A buffer overflow exists in iTunes when processing album cover art. By enticing a user to open a maliciously crafted music file, an attacker may trigger the overflow which may lead to an unexpected application termination or arbitrary code execution. This update addresses the issue by performing proper bounds checking.

Even if you don’t have the new iPods and won’t be needing support, this is an iTunes update you absolutely should apply. The patch is being delivered via the Mac’s automatic software update utility.

Manual download locations: iTunes 7.4 for Mac and iTunes 7.4 for Windows.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 46 Talkback(s)
Isn't that what Microsoft was doing in 2007 .
If anything , Microsoft isn't saying to much about it's products being buggy anymore .
Does anyone know why this is happening ?... (Read the rest)
Posted by: AdventTech67 Posted on: 01/13/08 You are currently: a Guest | | Terms of Use
Typical Apple operating procedure.  xuniL_z | 09/06/07
As oppose to Microsoft...  mrlinux | 09/06/07
Wow, obsess much?  NonZealot | 09/06/07
Not near as much as you do  MarcB_z | 09/06/07
NonZealot, I have bookmarked your post,  Joel R | 09/07/07
That's the funniest thing..  msalzberg | 09/08/07
No just showing the other side of the fence  mrlinux | 09/12/07
Let's pretend the threats are real.  mlindl | 09/07/07
Same here, mate.  xuniL_z | 09/07/07
Isn't that what Microsoft was doing in 2007 .  AdventTech67 | 01/13/08
To be fair, the company did issue a brief advisory with basic details of th  Non-Zealand | 09/06/07
Where?  Ryan NaraineZDNet Moderator | 09/06/07
Erm...  zkiwi | 09/06/07
I only quoted your own article...  Non-Zealand | 09/06/07
where???  richvball44 | 09/08/07
Why help the hackers??  Prime Detailer | 09/06/07
Because...  Ryan NaraineZDNet Moderator | 09/06/07
Good one.  frgough | 09/07/07
Equal Treatment  dwerk | 09/07/07
The game of hyperbole  frgough | 09/07/07
The game of reading  dwerk | 09/07/07
Hyperbole  frgough | 09/10/07
Really?  PghNative | 09/07/07
Plays together nicely on a PC too.  laura.b | 09/10/07
I skipped it  mlindl | 09/07/07
when  richvball44 | 09/08/07
Secunia  notlob | 09/08/07
RE: Apple plugs gaping iTunes hole, doesn't tell everyone  jbelkin | 09/06/07
Because he needs a new car  Kid Icarus-21097050858087920245213802267493 | 09/07/07
Very smart indeed. And Win2000 Users?  GiorgioM | 09/07/07
RE: Apple plugs gaping iTunes hole, doesn't tell everyone  alicat876 | 09/07/07
"To be fair, "  mlindl | 09/07/07
Can Macs be compromised?  butler360 | 09/07/07
Recent browers studies  laura.b | 09/10/07
Firefox on OSX (and Linux, for that matter)  nix_hed | 09/10/07
So what?  bonchi74@... | 09/08/07
the only gaping hole is the author's  bonchi74@... | 09/08/07
60 windows of what? (Mention of iTunes in here as well!)  Ben_E | 09/08/07
THANK YOU  laura.b | 09/10/07
True?  filker0 | 09/10/07
Let's compare  frabjous | 09/10/07
Mundane corporate stuff vs single task  NonZealot | 09/11/07
Doesn't this drama never end?  Solid Jedi Knight | 09/08/07
Precisely my point... (on and off topic post)  Ben_E | 09/08/07
RE: Apple plugs gaping iTunes hole, doesn't tell everyone  DannyO_0x98 | 09/10/07
RE: Apple plugs gaping iTunes hole, doesn't tell everyone  Timpraetor | 09/10/07

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here