VID |
50125 |
Severity |
30 |
Port |
3689 |
Protocol |
TCP |
Class |
SMB |
Detailed Description |
The version of Apple iTunes running on the remote host is prior to 12.6.1. It is, therefore, affected by a remote code execution vulnerability due to memory corruption caused by improper validation of user-supplied input. An unauthenticated, remote attacker can exploit this, by convincing a user to open maliciously crafted web content, to execute arbitrary code.
* References: https://support.apple.com/en-us/HT207805 https://lists.apple.com/archives/security-announce/2017/May/msg00002.html
* Platforms Affected: Apple Computer, Inc., iTunes versions prior to 12.6.1 |
Recommendation |
Upgrade to the latest version of iTunes (12.6.1 or later), available from the Apple Download Web site at http://www.apple.com/itunes/download/ |
Related URL |
CVE-2017-6984 (CVE) |
Related URL |
(SecurityFocus) |
Related URL |
(ISS) |
|