Vulnerabilities > CVE-2010-0531 - Resource Management Errors vulnerability in Apple Itunes
Attack vector
NETWORK Attack complexity
MEDIUM Privileges required
NONE Confidentiality impact
NONE Integrity impact
NONE Availability impact
PARTIAL Summary
Apple iTunes before 9.1 allows remote attackers to cause a denial of service (infinite loop) via a crafted MP4 podcast file.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
Nessus
NASL family MacOS X Local Security Checks NASL id MACOSX_ITUNES_9_1.NASL description The remote version of iTunes is older than 9.1. Such versions are potentially affected by multiple vulnerabilities : - An infinite loop in the application last seen 2020-06-01 modified 2020-06-02 plugin id 45389 published 2010-03-31 reporter This script is Copyright (C) 2010-2018 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/45389 title iTunes < 9.1 Multiple Vulnerabilities (Mac OS X) NASL family Windows NASL id ITUNES_9_1.NASL description The version of Apple iTunes installed on the remote Windows host is older than 9.1. Such versions may be affected by multiple vulnerabilities : - A buffer underflow in ImageIO last seen 2020-06-01 modified 2020-06-02 plugin id 45390 published 2010-03-31 reporter This script is Copyright (C) 2010-2018 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/45390 title Apple iTunes < 9.1 Multiple Vulnerabilities (credentialed check) NASL family Peer-To-Peer File Sharing NASL id ITUNES_9_1_BANNER.NASL description The version of Apple iTunes on the remote host is prior to version 9.1. It is, therefore, affected by multiple vulnerabilities : - A buffer underflow in ImageIO last seen 2020-06-01 modified 2020-06-02 plugin id 45391 published 2010-03-31 reporter This script is Copyright (C) 2010-2018 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/45391 title Apple iTunes < 9.1 Multiple Vulnerabilities (uncredentialed check)
Oval
accepted | 2015-06-22T04:00:49.475-04:00 | ||||||||||||||||||||||||
class | vulnerability | ||||||||||||||||||||||||
contributors |
| ||||||||||||||||||||||||
definition_extensions |
| ||||||||||||||||||||||||
description | Apple iTunes before 9.1 allows remote attackers to cause a denial of service (infinite loop) via a crafted MP4 podcast file. | ||||||||||||||||||||||||
family | windows | ||||||||||||||||||||||||
id | oval:org.mitre.oval:def:7427 | ||||||||||||||||||||||||
status | accepted | ||||||||||||||||||||||||
submitted | 2010-04-09T10:30:00.000-05:00 | ||||||||||||||||||||||||
title | Apple iTunes MP4 File Processing Denial of Service Vulnerability | ||||||||||||||||||||||||
version | 14 |