Lucene search

K
nessusTenable5894.PRM
HistoryApr 19, 2011 - 12:00 a.m.

iTunes < 10.2.2 Multiple Vulnerabilities

2011-04-1900:00:00
Tenable
www.tenable.com
18

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

EPSS

0.338

Percentile

97.1%

The remote host has iTunes installed, a popular media player for Windows and Mac OS.

Versions of iTunes earlier than 10.2.2 are potentially affected by several issues :

  • An integer overflow issue in the handling of nodesets could lead to a crash or arbitrary code execution. (CVE-2011-1290)

  • A use after free issue in the handling of text nodes could lead to a crash or arbitrary code execution. (CVE-2011-1344)

Binary data 5894.prm

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

EPSS

0.338

Percentile

97.1%