Apple has released the new iTunes 9.2.1 update. The update is responsible for a key security vulnerability that attackers can execute arbitrary code. The vulnerability affects both Windows and Mac computers using iTunes and an attacker can be exploited by a maliciously created ‘itpc:’ link for hijacking an end-user’s computer.
Secunia, the vulnerability of society to Danish intelligence, vulnerability (CVE-2010-1777) is the result of a boundary error caused by the manner in which specific uses iTunes ‘itpc:’ links, as reported by SoftPedia on July 20, 2010.
During an attack, the attacker creates a special URL and users visiting the towers. If you are able to exploit this vulnerability, then a situation of ‘heap overflow’ results that makes the computer susceptible to attack.
Apple states in a support document posted on its website that visiting a maliciously-created ‘itpc:’ URL may result in random code execution or sudden termination of application. Apple has set right the flaw via enhanced bounds checking, as reported by Apple on July 19, 2010.
According to security researchers, the rate on the shortcomings of the methods of URL handling is very risky worrying, since no technical skills needed for their operations.
They argue that, given the huge user base of iTunes after the acceptance of IPAD, iPhones and iPods, the security hole creates an opportunity for aggression in bulk.
Amid the multitude of problems solved, there are updates that address minor issues in the articles slipped to iTunes, the demand factor due to sync with some devices unlike before using iTunes 9.2 A problem with IOS and updating of four pieces on the iPhone and iPod encrypted backups, and the necessary breakthrough in performance and stability.
However, the most important problem to solve with the iTunes 9.2.1 update is that the desktop version earlier versions of some bad third party plug-ins.
The same type of vulnerability in Windows XP process hcp: (Help and Support) URL, a default of 0 days was revealed in early June 2010. The two targeted attacks and drive-by downloads, exploit this vulnerability.
RSS Feed
Posted in

