Apple iTunes Protocol Handler Buffer Overflow Vulnerabilities
3 Jun. 2009
Summary
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple iTunes. User interaction is required to exploit this vulnerability in that the target must visit a malicious page.
Vulnerable Systems:
* Apple iTunes prior to version 8.2
Immune Systems:
* Apple iTunes version 8.2 and later
The specific flaw exists in the URL handlers associated with iTunes. When processing URLs via the protocol handlers "itms", "itmss", "daap", "pcast", and "itpc" an exploitable stack overflow occurs. Successful exploitation can lead to a remote system compromise under the credentials of the currently logged in user.