English
The Internet threat alert status is currently normal. At present, no major epidemics or other serious incidents have been recorded by Kaspersky Lab’s monitoring service. Internet threat level: 1

Apple iTunes Multiple Vulnerabilities


Secunia ID

SA41149

CVE-ID

CVE-2010-1780, CVE-2010-1782, CVE-2010-1783, CVE-2010-1784, CVE-2010-1785, CVE-2010-1786, CVE-2010-1787, CVE-2010-1788, CVE-2010-1789, CVE-2010-1790, CVE-2010-1791, CVE-2010-1792, CVE-2010-1793

Release Date

02 Sep 2010

Criticality

Highly Critical

Solution Status

Unpatched

Software

Apple iTunes 9.x

Where

From remote

Impact
System access

This covers vulnerabilities where malicious people are able to gain system access and execute arbitrary code with the privileges of a local user.

Description

Multiple vulnerabilities have been reported in Apple iTunes, which can be exploited by malicious people to compromise a user's system.

The vulnerabilities are caused due to the use of vulnerable WebKit code.

For more information:
SA40664

Solution

Upgrade to version 10.

Original Advisory

Apple:
http://support.apple.com/kb/HT4328