Apple iTunes Software Update Spoofing Weakness

DiabloBlack

New Member
Thread author
Nov 5, 2011
193
For those who use Apple's iTunes.

Secunia Advisory SA46848

Apple iTunes security update from 10.5.0.x to 10.5.1.

Description:

A weakness has been reported in Apple iTunes, which can be exploited by malicious people to conduct spoofing attacks.

The weakness is caused due the software update mechanism using an HTTP request to check for new updates. This can be exploited to e.g. spoof an update via Man-in-the-Middle (MitM) attacks.

Successful exploitation requires that Apple Software Update is not installed.

The weakness is reported in versions prior to 10.5.1.

Secunia Details

Apple iTunes
 

AyeAyeCaptain

Level 1
Feb 24, 2011
585
Thanks for the link/info Diablo and I'm sure you like me have to come to find Secunia is a very useful addition for any user.
 

AyeAyeCaptain

Level 1
Feb 24, 2011
585
Rep +

Totally agree there, while it's not the answer/solution to becoming infected through insecure programs etc, it certainly is an added layer to reduce the risk. Besides, Itunes is bundled with the biggest security threat anyway, Quicktime surely?!! :p
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top