Stack-based buffer overflow vulnerability in Apple iTunes when parsing itms: URLs - APPLE-SA-2009-06-01-2 (Mac OS X)ID: oval:org.secpod.oval:def:4846 | Date: (C)2012-03-26 (M)2023-11-18 |
Class: PATCH | Family: macos |
The host is missing a security update according to Apple advisory, APPLE-SA-2009-06-01-2. The update is required to fix a buffer overflow vulnerability. A flaw is present in the application, which fails to handle a long URL component after a colon. Successful exploitation could allow attackers to execute arbitrary code or crash the service.
Platform: |
Apple Mac OS X 10.8 |
Apple Mac OS X 10.9 |
Apple Mac OS X 10.10 |
Apple Mac OS X Server 10.8 |
Apple Mac OS X Server 10.9 |
Apple Mac OS X Server 10.10 |