Sunday, 27 May 2012

About the security content of iTunes 10.5.1

To protect our customers, Apple does not disclose, discuss or confirm security issues until a full investigation and any necessary patches or releases are available. To learn more about Apple Product Security, see the Apple Product Security website.

For information about the key security products Apple PGP, see "How do I use to protect the products Apple PGP Key."

Where possible, CVE IDs are used to reference the vulnerabilities for more information.

To learn about other Security Updates, see "Security Updates Apple».
ITunes 10.5.1



      ITunes

      Available for: Mac OS X 10.5 or later, Windows 7, Vista, XP SP2 or later

      Consequences: The man-in-middle attacker may be able to offer software that appears to occur from Apple

      Description: ITunes periodically checks for software updates using an HTTP request to Apple. This requirement can lead to ITunes to show that an update is available. If the Apple Software Update for Windows, is not installed, clicking the Download ITunes can open the URL in the HTTP-response by default in the user's browser. This problem has been resolved with the help of a secure connection when checking for updates. For the system OS X, the default user's browser is not used, because the Apple Software Update is included in OS X, however, this change adds defense in depth.

      CVE-ID

      CVE-2008-3434: Francisco Amato of Infobyte Security Research



Important: Mention of third-party Web sites and products for informational purposes only and constitutes neither an endorsement nor a recommendation. Apple is not responsible for selection, performance or use of the information or products on third-party Web sites. Apple provides this only for the convenience of our users. Apple has not tested the information found on these sites and makes no representation as to the accuracy or reliability. There are risks associated with the use of any information or products found on the Internet, and Apple assumes no responsibility in this regard. It should be understood that the third-party site is independent from Apple, and Apple, has no control over the content on this site. Please contact the vendor for additional information.

No comments:

Post a Comment