Vulnerabilities > CVE-2008-3636 - Numeric Errors vulnerability in Apple Itunes

047910
CVSS 7.2 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
local
low complexity
apple
CWE-189
nessus

Summary

Integer overflow in the IopfCompleteRequest API in the kernel in Microsoft Windows 2000, XP, Server 2003, and Vista allows context-dependent attackers to gain privileges. NOTE: this issue was originally reported for GEARAspiWDM.sys 2.0.7.5 in Gear Software CD DVD Filter driver before 4.001.7, as used in other products including Apple iTunes and multiple Symantec and Norton products, which allows local users to gain privileges via repeated IoAttachDevice IOCTL calls to \\.\GEARAspiWDMDevice in this GEARAspiWDM.sys. However, the root cause is the integer overflow in the API call itself.

Common Weakness Enumeration (CWE)

Nessus

  • NASL familyPeer-To-Peer File Sharing
    NASL idITUNES_8_0_BANNER.NASL
    descriptionThe version of Apple iTunes on the remote host is prior to version 8.0. It is, therefore, affected by an integer buffer overflow vulnerability in an included third party driver. A local user can exploit this to gain system privileges.
    last seen2020-06-01
    modified2020-06-02
    plugin id34158
    published2008-09-10
    reporterThis script is Copyright (C) 2008-2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/34158
    titleApple iTunes < 8.0 Integer Buffer Overflow (uncredentialed check)
  • NASL familyWindows
    NASL idITUNES_8_0.NASL
    descriptionThe version of Apple iTunes installed on the remote Windows host is older than 8.0. Such versions include a third-party driver that are affected by an integer buffer overflow that could allow a local user to gain system privileges.
    last seen2020-06-01
    modified2020-06-02
    plugin id34157
    published2008-09-10
    reporterThis script is Copyright (C) 2008-2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/34157
    titleApple iTunes < 8.0 Integer Buffer Overflow (credentialed check)

Oval

accepted2015-06-22T04:00:46.317-04:00
classvulnerability
contributors
  • nameChandan S
    organizationSecPod Technologies
  • nameMike Lah
    organizationThe MITRE Corporation
  • nameScott Quint
    organizationQuintechssential
  • namePooja Shetty
    organizationSecPod Technologies
  • nameMaria Kedovskaya
    organizationALTX-SOFT
  • nameShane Shaffer
    organizationG2, Inc.
  • nameMaria Kedovskaya
    organizationALTX-SOFT
  • nameBernd Eggenmueller
    organizationbaramundi software
definition_extensions
commentApple iTunes is installed
ovaloval:org.mitre.oval:def:12353
descriptionInteger overflow in the IopfCompleteRequest API in the kernel in Microsoft Windows 2000, XP, Server 2003, and Vista allows context-dependent attackers to gain privileges. NOTE: this issue was originally reported for GEARAspiWDM.sys 2.0.7.5 in Gear Software CD DVD Filter driver before 4.001.7, as used in other products including Apple iTunes and multiple Symantec and Norton products, which allows local users to gain privileges via repeated IoAttachDevice IOCTL calls to \\.\GEARAspiWDMDevice in this GEARAspiWDM.sys. However, the root cause is the integer overflow in the API call itself.
familywindows
idoval:org.mitre.oval:def:6035
statusaccepted
submitted2008-09-17T13:25:15
titleApple iTunes Local Privilege Escalation Vulnerability
version15

Seebug

  • bulletinFamilyexploit
    descriptionCVE ID:CVE-2008-3636 CNCVE ID:CNCVE-20083636 多个Symantec产品存在漏洞,允许本地攻击者提升特权。 问题是由于第三方驱动 &quot;GEARspiWDM.sys&quot;在处理来自用户空间应用程序的数据时缺少输入验证错误,允许恶意用户多次调用&quot;IoAttachDevice&quot;而使Windows内核触发整数溢出,导致以SYSTEM权限执行任意代码。 Symantec Gear Device Driver 目前没有解决方案提供: <a href=http://www.symantec.com target=_blank>http://www.symantec.com</a>
    idSSV:4194
    last seen2017-11-19
    modified2008-10-13
    published2008-10-13
    reporterRoot
    titleSymantec Gear Device Driver本地特权提升漏洞
  • bulletinFamilyexploit
    descriptionBUGTRAQ ID: 31089 CVE ID:CVE-2008-3636 CNCVE ID:CNCVE-20083636 Apple iTunes是一款媒体播放程序。 Apple iTunes提供的第三方驱动存在整数溢出,本地攻击者可以利用漏洞获得系统特权。 目前没有详细漏洞细节提供。 eSignal eSignal 6.0.2 Apple iTunes 7.3.2 Apple iTunes 7.3.1 Apple iTunes 7.3 Apple iTunes 7.0.2 Apple iTunes 6.0.5 Apple iTunes 6.0.4 Apple iTunes 6.0.3 Apple iTunes 6.0.1 Apple iTunes 6.0 Apple iTunes 7.4 升级到最新版本: Apple iTunes 7.4 Apple iTunes8Setup.exe <a href=https://swdlp.apple.com/cgi-bin/WebObjects/SoftwareDownloadApp.woa/140 target=_blank>https://swdlp.apple.com/cgi-bin/WebObjects/SoftwareDownloadApp.woa/140</a> 9/wo/MtdZoeP1oC9nnz5IOwriMg/2.5 Apple iTunes 6.0 Apple iTunes8Setup.exe <a href=https://swdlp.apple.com/cgi-bin/WebObjects/SoftwareDownloadApp.woa/140 target=_blank>https://swdlp.apple.com/cgi-bin/WebObjects/SoftwareDownloadApp.woa/140</a> 9/wo/MtdZoeP1oC9nnz5IOwriMg/2.5
    idSSV:4029
    last seen2017-11-19
    modified2008-09-11
    published2008-09-11
    reporterRoot
    titleApple iTunes第三方驱动本地特权提升漏洞