---------------------------------------------------------------------- We have updated our website, enjoy! http://secunia.com/ ---------------------------------------------------------------------- TITLE: Apple iTunes Privilege Escalation Vulnerability SECUNIA ADVISORY ID: SA31824 VERIFY ADVISORY: http://secunia.com/advisories/31824/ CRITICAL: Less critical IMPACT: Privilege escalation WHERE: Local system SOFTWARE: iTunes 7.x http://secunia.com/advisories/product/12131/ DESCRIPTION: A vulnerability has been reported in Apple iTunes, which can be exploited by malicious, local users to gain escalated privileges. The vulnerability is caused due to an integer overflow in a bundled third-party driver and may be exploited to execute arbitrary code with escalated privileges on a Windows system. NOTE: A misleading firewall warning dialog has also been reported when iTunes Music Sharing has been configured to be blocked on Mac OS X. The dialog will incorrectly state that unblocking iTunes Music Sharing does not affect the firewall's security. SOLUTION: Upgrade to version 8.0. iTunes 8 for Macintosh: http://www.apple.com/support/downloads/itunes8formacintosh.html iTunes 8 for Windows: http://www.apple.com/support/downloads/itunes8forwindows.html PROVIDED AND/OR DISCOVERED BY: The vendor credits Ruben Santamarta, Wintercore. The vendor also credits Eric Hall, DarkArt Consulting Services for reporting the misleading firewall dialog. ORIGINAL ADVISORY: Apple: http://support.apple.com/kb/HT3025 ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help everybody keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/advisories/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/advisories/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ----------------------------------------------------------------------