[Full-disclosure] -Advisory- $ -Thu Mar 16 13:40:19 EST 2006- $ Buffer Overflow in Apple iTunes

brian at dessent.net brian at dessent.net
Thu Mar 16 18:40:27 GMT 2006




-Advisory- $ -Thu Mar 16 13:40:19 EST 2006- $ Buffer Overflow in Apple iTunes




====
o/ 卍 BACKGROUND
There is no background.
====
卍 \o DESCRIPTION
It is possible to make Apple iTunes crash or run arbitrary code by the use of malformed input.

====
o/ 卍 VENDOR RESPONSE
Apple iTunes was presented no explanation regarding the vulnerability at hand.
====
卍 \o CVE INFORMATION
The Common Vulnerabilities and Exposures (CVE) project has assigned the name CVE-2006-553699 to this issue

====
APPENDIX A VENDOR INFORMATION
http://www.apple.com/itunes/





Full-Disclosure is hosted and sponsored by Secunia.