Software exposes users to remote code execution vulnerability
Shaun Nichols in California, vnunet.com07 Sep 2007
ADVERTISEMENT
Apple has
included a fix for a remote code execution vulnerability for the OS X and
Windows versions of its latest
iTunes
7.4 release.
The software was unveiled on 5 September to support a
new range of iPods
and a ring-tone builder.
The vulnerability lies in the cover art display system used by iTunes. Cover
art is displayed while a track is playing, but is also used to navigate music in
the Cover Flow interface.
By creating a specially malformed file, an attacker could cause an
application crash or execute arbitrary code.
Remote code execution flaws are considered to be the most serious type of
vulnerability, because they can be used by attackers to install malware.
Apple credited David Thiel, a security researcher at
iSec
Partners, with discovering the vulnerability.
Security firm
Secunia
rated the flaw as 'highly critical', the second highest of its alert levels.
Secunia and the
US
Computer Emergency Readiness Team recommended that users install the update
as soon as possible.
ITunes has yet to fall victim to a major attack, but other Apple products
have been targeted by malware authors.
Background A fantastic opportunity has just arisen within this growing multinational organisation. Working as an EMEA Advisory Consultant your main duties and responsibilities will be to provide advice and support to international organisations looking to ... more >
This is a hands-on development team lead position that will push you to the limit of your architectural and mentoring capabilities. Technical amp; development (Agile) • Create effective data solutions, in partnership with the relevant ... more >
C++ Research Developer Global Pharmaceutical Company London C++ Research Developer Biotechology Global Medical Company London Global Biotechnology Company specialising in the research and development of cutting edge health care products is looking for an innovative, ... more >
Junior Network Operations Engineer – Borehamwood - £24k Junior / entry level network operations engineer required, will be responsible for supporting external clients network and security solutions. Excellent entry level position as my client offers ... more >More job opportunities