Vulnerabilities > CVE-2013-1038 - Buffer Errors vulnerability in Apple Iphone OS, Itunes and Safari

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
apple
CWE-119
nessus

Summary

WebKit, as used in Apple iOS before 7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-09-18-2.

Vulnerable Configurations

Part Description Count
Application
Apple
293
OS
Apple
50

Common Attack Pattern Enumeration and Classification (CAPEC)

  • Buffer Overflow via Environment Variables
    This attack pattern involves causing a buffer overflow through manipulation of environment variables. Once the attacker finds that they can modify an environment variable, they may try to overflow associated buffers. This attack leverages implicit trust often placed in environment variables.
  • Overflow Buffers
    Buffer Overflow attacks target improper or missing bounds checking on buffer operations, typically triggered by input injected by an attacker. As a consequence, an attacker is able to write past the boundaries of allocated buffer regions in memory, causing a program crash or potentially redirection of execution as per the attackers' choice.
  • Client-side Injection-induced Buffer Overflow
    This type of attack exploits a buffer overflow vulnerability in targeted client software through injection of malicious content from a custom-built hostile service.
  • Filter Failure through Buffer Overflow
    In this attack, the idea is to cause an active filter to fail by causing an oversized transaction. An attacker may try to feed overly long input strings to the program in an attempt to overwhelm the filter (by causing a buffer overflow) and hoping that the filter does not fail securely (i.e. the user input is let into the system unfiltered).
  • MIME Conversion
    An attacker exploits a weakness in the MIME conversion routine to cause a buffer overflow and gain control over the mail server machine. The MIME system is designed to allow various different information formats to be interpreted and sent via e-mail. Attack points exist when data are converted to MIME compatible format and back.

Nessus

  • NASL familyWindows
    NASL idITUNES_11_1_4.NASL
    descriptionThe version of Apple iTunes installed on the remote Windows host is older than 11.1.4. It is, therefore, potentially affected by several issues : - The included versions of WebKit, libxml, and libxslt contain several errors that could lead to memory corruption and possibly arbitrary code execution. The vendor notes that one possible attack vector is a man-in-the-middle attack while the application browses the
    last seen2020-06-01
    modified2020-06-02
    plugin id72104
    published2014-01-23
    reporterThis script is Copyright (C) 2014-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/72104
    titleApple iTunes < 11.1.4 Multiple Vulnerabilities (credentialed check)
    code
    #
    # (C) Tenable Network Security, Inc.
    #
    
    include("compat.inc");
    
    if (description)
    {
      script_id(72104);
      script_version("1.7");
      script_cvs_date("Date: 2019/11/26");
    
      script_cve_id(
        "CVE-2011-3102",
        "CVE-2012-0841",
        "CVE-2012-2807",
        "CVE-2012-2825",
        "CVE-2012-2870",
        "CVE-2012-2871",
        "CVE-2012-5134",
        "CVE-2013-1024",
        "CVE-2013-1037",
        "CVE-2013-1038",
        "CVE-2013-1039",
        "CVE-2013-1040",
        "CVE-2013-1041",
        "CVE-2013-1042",
        "CVE-2013-1043",
        "CVE-2013-1044",
        "CVE-2013-1045",
        "CVE-2013-1046",
        "CVE-2013-1047",
        "CVE-2013-2842",
        "CVE-2013-5125",
        "CVE-2013-5126",
        "CVE-2013-5127",
        "CVE-2013-5128",
        "CVE-2014-1242"
      );
      script_bugtraq_id(
        52107,
        53540,
        54203,
        54718,
        55331,
        56684,
        60067,
        60368,
        62551,
        62553,
        62554,
        62556,
        62557,
        62558,
        62559,
        62560,
        62563,
        62565,
        62567,
        62568,
        62569,
        62570,
        62571,
        65088
      );
      script_xref(name:"APPLE-SA", value:"APPLE-SA-2014-01-22-1");
    
      script_name(english:"Apple iTunes < 11.1.4 Multiple Vulnerabilities (credentialed check)");
      script_summary(english:"Checks version of iTunes on Windows");
    
      script_set_attribute(attribute:"synopsis", value:
    "The remote host contains an application that has multiple
    vulnerabilities.");
      script_set_attribute(attribute:"description", value:
    "The version of Apple iTunes installed on the remote Windows host is
    older than 11.1.4. It is, therefore, potentially affected by several
    issues :
    
      - The included versions of WebKit, libxml, and libxslt
        contain several errors that could lead to memory
        corruption and possibly arbitrary code execution. The
        vendor notes that one possible attack vector is a
        man-in-the-middle attack while the application browses
        the 'iTunes Store'. (CVE-2011-3102, CVE-2012-0841,
        CVE-2012-2807, CVE-2012-2825, CVE-2012-2870,
        CVE-2012-2871, CVE-2012-5134, CVE-2013-1037,
        CVE-2013-1038, CVE-2013-1039, CVE-2013-1040,
        CVE-2013-1041, CVE-2013-1042, CVE-2013-1043,
        CVE-2013-1044, CVE-2013-1045, CVE-2013-1046,
        CVE-2013-1047, CVE-2013-2842, CVE-2013-5125,
        CVE-2013-5126, CVE-2013-5127, CVE-2013-5128)
    
      - An error exists related to text tracks in movie files
        that could allow denial of service or arbitrary code
        execution. (CVE-2013-1024)
    
      - An error exists related to the iTunes Tutorials window
        that could allow an attacker in a privileged network
        location to inject content. (CVE-2014-1242)");
      script_set_attribute(attribute:"see_also", value:"http://support.apple.com/kb/HT6001");
      script_set_attribute(attribute:"see_also", value:"http://www.securityfocus.com/archive/1/530870/30/0/threaded");
      script_set_attribute(attribute:"solution", value:
    "Upgrade to Apple iTunes 11.1.4 or later.");
      script_set_cvss_base_vector("CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P");
      script_set_cvss_temporal_vector("CVSS2#E:POC/RL:OF/RC:C");
      script_set_attribute(attribute:"cvss_score_source", value:"CVE-2013-2842");
    
      script_set_attribute(attribute:"exploitability_ease", value:"Exploits are available");
      script_set_attribute(attribute:"exploit_available", value:"true");
    
      script_set_attribute(attribute:"vuln_publication_date", value:"2013/10/22");
      script_set_attribute(attribute:"patch_publication_date", value:"2014/01/22");
      script_set_attribute(attribute:"plugin_publication_date", value:"2014/01/23");
    
      script_set_attribute(attribute:"plugin_type", value:"local");
      script_set_attribute(attribute:"cpe", value:"cpe:/a:apple:itunes");
      script_end_attributes();
    
      script_category(ACT_GATHER_INFO);
      script_family(english:"Windows");
    
      script_copyright(english:"This script is Copyright (C) 2014-2019 and is owned by Tenable, Inc. or an Affiliate thereof.");
    
      script_dependencies("itunes_detect.nasl");
      script_require_keys("SMB/iTunes/Version");
    
      exit(0);
    }
    
    
    include("audit.inc");
    include("global_settings.inc");
    include("misc_func.inc");
    
    
    version = get_kb_item_or_exit("SMB/iTunes/Version");
    path = get_kb_item_or_exit("SMB/iTunes/Path");
    
    fixed_version = "11.1.4.62";
    if (ver_compare(ver:version, fix:fixed_version) < 0)
    {
      port = get_kb_item("SMB/transport");
      if (!port) port = 445;
    
      if (report_verbosity > 0)
      {
        report =
          '\n  Path              : '+path+
          '\n  Installed version : '+version+
          '\n  Fixed version     : '+fixed_version+'\n';
        security_hole(port:port, extra:report);
      }
      else security_hole(port);
    }
    else audit(AUDIT_INST_PATH_NOT_VULN, "iTunes", version, path);
    
  • NASL familyMacOS X Local Security Checks
    NASL idMACOSX_SAFARI6_1.NASL
    descriptionThe version of Apple Safari installed on the remote Mac OS X 10.7 or 10.8 host is earlier than 6.1. It is, therefore, potentially affected by several issues : - A bounds-checking issue exists related to handling XML files. (CVE-2013-1036) - Multiple memory corruption vulnerabilities exist in WebKit that could lead to unexpected program termination or arbitrary code execution. (CVE-2013-1037, CVE-2013-1038, CVE-2013-1039, CVE-2013-1040, CVE-2013-1041, CVE-2013-1042, CVE-2013-1043, CVE-2013-1044, CVE-2013-1045, CVE-2013-1046, CVE-2013-1047, CVE-2013-2842, CVE-2013-5125, CVE-2013-5126, CVE-2013-5127, CVE-2013-5128) - An error exists related to URL handling that could lead to information disclosure. (CVE-2013-2848) - A cross-site scripting issue exists in WebKit
    last seen2020-06-01
    modified2020-06-02
    plugin id70563
    published2013-10-23
    reporterThis script is Copyright (C) 2013-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/70563
    titleMac OS X : Apple Safari < 6.1 Multiple Vulnerabilities
    code
    #
    # (C) Tenable Network Security, Inc.
    #
    
    include("compat.inc");
    
    if (description)
    {
      script_id(70563);
      script_version("1.7");
      script_cvs_date("Date: 2019/11/27");
    
      script_cve_id(
        "CVE-2013-1036",
        "CVE-2013-1037",
        "CVE-2013-1038",
        "CVE-2013-1039",
        "CVE-2013-1040",
        "CVE-2013-1041",
        "CVE-2013-1042",
        "CVE-2013-1043",
        "CVE-2013-1044",
        "CVE-2013-1045",
        "CVE-2013-1046",
        "CVE-2013-1047",
        "CVE-2013-2842",
        "CVE-2013-2848",
        "CVE-2013-5125",
        "CVE-2013-5126",
        "CVE-2013-5127",
        "CVE-2013-5128",
        "CVE-2013-5129",
        "CVE-2013-5130",
        "CVE-2013-5131",
        "CVE-2013-7127"
      );
      script_bugtraq_id(
        60067,
        60073,
        62537,
        62539,
        62541,
        62551,
        62553,
        62554,
        62556,
        62557,
        62558,
        62559,
        62560,
        62563,
        62565,
        62567,
        62568,
        62569,
        62570,
        62571,
        63289,
        64409
      );
      script_xref(name:"APPLE-SA", value:"APPLE-SA-2013-10-22-2");
    
      script_name(english:"Mac OS X : Apple Safari < 6.1 Multiple Vulnerabilities");
      script_summary(english:"Check the Safari SourceVersion");
    
      script_set_attribute(attribute:"synopsis", value:
    "The remote host contains a web browser that is affected by several
    vulnerabilities.");
      script_set_attribute(attribute:"description", value:
    "The version of Apple Safari installed on the remote Mac OS X 10.7 or
    10.8 host is earlier than 6.1. It is, therefore, potentially affected
    by several issues :
    
      - A bounds-checking issue exists related to handling XML
        files. (CVE-2013-1036)
    
      - Multiple memory corruption vulnerabilities exist in
        WebKit that could lead to unexpected program termination
        or arbitrary code execution. (CVE-2013-1037,
        CVE-2013-1038, CVE-2013-1039, CVE-2013-1040,
        CVE-2013-1041, CVE-2013-1042, CVE-2013-1043,
        CVE-2013-1044, CVE-2013-1045, CVE-2013-1046,
        CVE-2013-1047, CVE-2013-2842, CVE-2013-5125,
        CVE-2013-5126, CVE-2013-5127, CVE-2013-5128)
    
      - An error exists related to URL handling that could lead
        to information disclosure. (CVE-2013-2848)
    
      - A cross-site scripting issue exists in WebKit's handling
        of URLs and drag-and-drop operations. (CVE-2013-5129,
        CVE-2013-5131)
    
      - Using 'Web Inspector' could negate 'Private Browsing'
        protections leading to information disclosure.
        (CVE-2013-5130)
    
      - An error exists related to the 'Reopen All Windows
        from Last Session' feature that could allow a local
        attacker to obtain plaintext user ID and password
        information from the 'LastSession.plist' file.
        (CVE-2013-7127)");
      script_set_attribute(attribute:"see_also", value:"http://support.apple.com/kb/HT6000");
      script_set_attribute(attribute:"see_also", value:"http://lists.apple.com/archives/security-announce/2013/Oct/msg00003.html");
      script_set_attribute(attribute:"see_also", value:"http://www.securelist.com/en/blog/8168/Loophole_in_Safari");
      script_set_attribute(attribute:"solution", value:
    "Upgrade to Apple Safari 6.1 or later.");
      script_set_cvss_base_vector("CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P");
      script_set_cvss_temporal_vector("CVSS2#E:POC/RL:OF/RC:C");
      script_set_attribute(attribute:"cvss_score_source", value:"CVE-2013-2842");
    
      script_set_attribute(attribute:"exploitability_ease", value:"Exploits are available");
      script_set_attribute(attribute:"exploit_available", value:"true");
      script_cwe_id(20, 74, 79, 442, 629, 711, 712, 722, 725, 750, 751, 800, 801, 809, 811, 864, 900, 928, 931, 990);
    
      script_set_attribute(attribute:"vuln_publication_date", value:"2013/10/22");
      script_set_attribute(attribute:"patch_publication_date", value:"2013/10/22");
      script_set_attribute(attribute:"plugin_publication_date", value:"2013/10/23");
    
      script_set_attribute(attribute:"plugin_type", value:"local");
      script_set_attribute(attribute:"cpe", value:"cpe:/a:apple:safari");
      script_end_attributes();
    
      script_category(ACT_GATHER_INFO);
      script_family(english:"MacOS X Local Security Checks");
    
      script_copyright(english:"This script is Copyright (C) 2013-2019 and is owned by Tenable, Inc. or an Affiliate thereof.");
    
      script_dependencies("macosx_Safari31.nasl");
      script_require_keys("Host/local_checks_enabled", "Host/MacOSX/Version", "MacOSX/Safari/Installed");
    
      exit(0);
    }
    
    include("audit.inc");
    include("global_settings.inc");
    include("misc_func.inc");
    
    if (!get_kb_item("Host/local_checks_enabled")) audit(AUDIT_LOCAL_CHECKS_NOT_ENABLED);
    os = get_kb_item("Host/MacOSX/Version");
    if (!os) audit(AUDIT_OS_NOT, "Mac OS X");
    
    if (!ereg(pattern:"Mac OS X 10\.[78]([^0-9]|$)", string:os)) audit(AUDIT_OS_NOT, "Mac OS X 10.7 / 10.8");
    
    get_kb_item_or_exit("MacOSX/Safari/Installed");
    path = get_kb_item_or_exit("MacOSX/Safari/Path", exit_code:1);
    version = get_kb_item_or_exit("MacOSX/Safari/Version", exit_code:1);
    
    fixed_version = "6.1";
    
    if (ver_compare(ver:version, fix:fixed_version, strict:FALSE) == -1)
    {
      set_kb_item(name:"www/0/XSS", value:TRUE);
    
      if (report_verbosity > 0)
      {
        report =
          '\n  Path              : ' + path +
          '\n  Installed version : ' + version +
          '\n  Fixed version     : ' + fixed_version + '\n';
        security_hole(port:0, extra:report);
      }
      else security_hole(0);
    }
    else audit(AUDIT_INST_PATH_NOT_VULN, "Safari", version, path);
    
  • NASL familyPeer-To-Peer File Sharing
    NASL idITUNES_11_1_2_BANNER.NASL
    descriptionThe version of Apple iTunes on the remote host is prior to version 11.1.2. It is, therefore, affected by multiple vulnerabilities : - An uninitialized memory access error exists in the handling of text tracks. By using a specially crafted movie file, a remote attacker can exploit this to cause a denial of service or execute arbitrary code. (CVE-2013-1024) - The included versions of the WebKit, libxml, and libxslt components in iTunes contain several errors that can lead to memory corruption and arbitrary code execution. The vendor states that one possible vector is a man-in- the-middle attack while the application browses the
    last seen2020-06-01
    modified2020-06-02
    plugin id70589
    published2013-10-24
    reporterThis script is Copyright (C) 2013-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/70589
    titleApple iTunes < 11.1.2 Multiple Vulnerabilities (uncredentialed check)
    code
    #
    # (C) Tenable Network Security, Inc.
    #
    
    include("compat.inc");
    
    if (description)
    {
      script_id(70589);
      script_version("1.8");
      script_cvs_date("Date: 2019/11/27");
    
      script_cve_id(
        "CVE-2011-3102",
        "CVE-2012-0841",
        "CVE-2012-2807",
        "CVE-2012-2825",
        "CVE-2012-2870",
        "CVE-2012-2871",
        "CVE-2012-5134",
        "CVE-2013-1024",
        "CVE-2013-1037",
        "CVE-2013-1038",
        "CVE-2013-1039",
        "CVE-2013-1040",
        "CVE-2013-1041",
        "CVE-2013-1042",
        "CVE-2013-1043",
        "CVE-2013-1044",
        "CVE-2013-1045",
        "CVE-2013-1046",
        "CVE-2013-1047",
        "CVE-2013-2842",
        "CVE-2013-5125",
        "CVE-2013-5126",
        "CVE-2013-5127",
        "CVE-2013-5128"
      );
      script_bugtraq_id(
        52107,
        53540,
        54203,
        54718,
        55331,
        56684,
        60067,
        60368,
        62551,
        62553,
        62554,
        62556,
        62557,
        62558,
        62559,
        62560,
        62563,
        62565,
        62567,
        62568,
        62569,
        62570,
        62571
      );
      script_xref(name:"APPLE-SA", value:"APPLE-SA-2013-10-22-8");
    
      script_name(english:"Apple iTunes < 11.1.2 Multiple Vulnerabilities (uncredentialed check)");
      script_summary(english:"Checks the version of iTunes.");
    
      script_set_attribute(attribute:"synopsis", value:
    "The remote host contains a multimedia application that has multiple
    vulnerabilities.");
      script_set_attribute(attribute:"description", value:
    "The version of Apple iTunes on the remote host is prior to version
    11.1.2. It is, therefore, affected by multiple vulnerabilities :
    
      - An uninitialized memory access error exists in the
        handling of text tracks. By using a specially crafted
        movie file, a remote attacker can exploit this to cause
        a denial of service or execute arbitrary code.
        (CVE-2013-1024)
    
      - The included versions of the WebKit, libxml, and libxslt
        components in iTunes contain several errors that can
        lead to memory corruption and arbitrary code execution.
        The vendor states that one possible vector is a man-in-
        the-middle attack while the application browses the
        'iTunes Store'.
        (CVE-2011-3102, CVE-2012-0841, CVE-2012-2807,
        CVE-2012-2825, CVE-2012-2870, CVE-2012-2871,
        CVE-2012-5134, CVE-2013-1037, CVE-2013-1038,
        CVE-2013-1039, CVE-2013-1040, CVE-2013-1041,
        CVE-2013-1042, CVE-2013-1043, CVE-2013-1044,
        CVE-2013-1045, CVE-2013-1046, CVE-2013-1047,
        CVE-2013-2842, CVE-2013-5125, CVE-2013-5126,
        CVE-2013-5127, CVE-2013-5128)");
      # https://web.archive.org/web/20131026094619/http://support.apple.com/kb/HT6001
      script_set_attribute(attribute:"see_also", value:"http://www.nessus.org/u?c88f1609");
      script_set_attribute(attribute:"see_also", value:"https://lists.apple.com/archives/security-announce/2013/Oct/msg00009.html");
      script_set_attribute(attribute:"solution", value:
    "Upgrade to Apple iTunes 11.1.2 or later.");
      script_set_cvss_base_vector("CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P");
      script_set_cvss_temporal_vector("CVSS2#E:POC/RL:OF/RC:C");
      script_set_attribute(attribute:"cvss_score_source", value:"CVE-2013-2842");
    
      script_set_attribute(attribute:"exploitability_ease", value:"Exploits are available");
      script_set_attribute(attribute:"exploit_available", value:"true");
    
      script_set_attribute(attribute:"vuln_publication_date", value:"2013/10/22");
      script_set_attribute(attribute:"patch_publication_date", value:"2013/10/22");
      script_set_attribute(attribute:"plugin_publication_date", value:"2013/10/24");
    
      script_set_attribute(attribute:"plugin_type", value:"remote");
      script_set_attribute(attribute:"cpe", value:"cpe:/a:apple:itunes");
      script_end_attributes();
    
      script_category(ACT_GATHER_INFO);
      script_family(english:"Peer-To-Peer File Sharing");
    
      script_copyright(english:"This script is Copyright (C) 2013-2019 and is owned by Tenable, Inc. or an Affiliate thereof.");
    
      script_dependencies("itunes_sharing.nasl");
      script_require_keys("iTunes/sharing");
      script_require_ports("Services/www", 3689);
    
      exit(0);
    }
    
    include("audit.inc");
    include("global_settings.inc");
    include("misc_func.inc");
    include("http.inc");
    
    port = get_http_port(default:3689, embedded:TRUE, ignore_broken:TRUE);
    
    get_kb_item_or_exit("iTunes/" + port + "/enabled");
    
    type = get_kb_item_or_exit("iTunes/" + port + "/type");
    source = get_kb_item_or_exit("iTunes/" + port + "/source");
    version = get_kb_item_or_exit("iTunes/" + port + "/version");
    
    if (type != 'Windows') audit(AUDIT_OS_NOT, "Windows");
    
    fixed_version = "11.1.2";
    
    if (ver_compare(ver:version, fix:fixed_version, strict:FALSE) == -1)
    {
      if (report_verbosity > 0)
      {
        report = '\n  Version source    : ' + source +
                 '\n  Installed version : ' + version +
                 '\n  Fixed version     : ' + fixed_version + '\n';
        security_hole(port:port, extra:report);
      }
      else security_hole(port);
    }
    else audit(AUDIT_LISTEN_NOT_VULN, "iTunes", port, version);
    
  • NASL familyWindows
    NASL idITUNES_11_1_2.NASL
    descriptionThe version of Apple iTunes installed on the remote Windows host is older than 11.1.2. It is, therefore, potentially affected by several issues : - An uninitialized memory access issue exists in the handling of text tracks, which could lead to memory corruption and possibly arbitrary code execution. (CVE-2013-1024) - The included versions of WebKit, libxml, and libxslt contain several errors that could lead to memory corruption and possibly arbitrary code execution. The vendor notes that one possible attack vector is a man-in-the-middle attack while the application browses the
    last seen2020-06-01
    modified2020-06-02
    plugin id70588
    published2013-10-24
    reporterThis script is Copyright (C) 2013-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/70588
    titleApple iTunes < 11.1.2 Multiple Vulnerabilities (credentialed check)
    code
    #
    # (C) Tenable Network Security, Inc.
    #
    
    include("compat.inc");
    
    if (description)
    {
      script_id(70588);
      script_version("1.7");
      script_cvs_date("Date: 2019/11/27");
    
      script_cve_id(
        "CVE-2011-3102",
        "CVE-2012-0841",
        "CVE-2012-2807",
        "CVE-2012-2825",
        "CVE-2012-2870",
        "CVE-2012-2871",
        "CVE-2012-5134",
        "CVE-2013-1024",
        "CVE-2013-1037",
        "CVE-2013-1038",
        "CVE-2013-1039",
        "CVE-2013-1040",
        "CVE-2013-1041",
        "CVE-2013-1042",
        "CVE-2013-1043",
        "CVE-2013-1044",
        "CVE-2013-1045",
        "CVE-2013-1046",
        "CVE-2013-1047",
        "CVE-2013-2842",
        "CVE-2013-5125",
        "CVE-2013-5126",
        "CVE-2013-5127",
        "CVE-2013-5128"
      );
      script_bugtraq_id(
        52107,
        53540,
        54203,
        54718,
        55331,
        56684,
        60067,
        60368,
        62551,
        62553,
        62554,
        62556,
        62557,
        62558,
        62559,
        62560,
        62563,
        62565,
        62567,
        62568,
        62569,
        62570,
        62571
      );
      script_xref(name:"APPLE-SA", value:"APPLE-SA-2013-10-22-8");
    
      script_name(english:"Apple iTunes < 11.1.2 Multiple Vulnerabilities (credentialed check)");
      script_summary(english:"Checks version of iTunes on Windows");
    
      script_set_attribute(attribute:"synopsis", value:
    "The remote host contains an application that has multiple
    vulnerabilities.");
      script_set_attribute(attribute:"description", value:
    "The version of Apple iTunes installed on the remote Windows host is
    older than 11.1.2. It is, therefore, potentially affected by several
    issues :
    
      - An uninitialized memory access issue exists in the
        handling of text tracks, which could lead to memory
        corruption and possibly arbitrary code execution.
        (CVE-2013-1024)
    
      - The included versions of WebKit, libxml, and libxslt
        contain several errors that could lead to memory
        corruption and possibly arbitrary code execution. The
        vendor notes that one possible attack vector is a
        man-in-the-middle attack while the application browses
        the 'iTunes Store'.
        (CVE-2011-3102, CVE-2012-0841, CVE-2012-2807,
        CVE-2012-2825, CVE-2012-2870, CVE-2012-2871,
        CVE-2012-5134, CVE-2013-1037, CVE-2013-1038,
        CVE-2013-1039, CVE-2013-1040, CVE-2013-1041,
        CVE-2013-1042, CVE-2013-1043, CVE-2013-1044,
        CVE-2013-1045, CVE-2013-1046, CVE-2013-1047,
        CVE-2013-2842, CVE-2013-5125, CVE-2013-5126,
        CVE-2013-5127, CVE-2013-5128)");
      script_set_attribute(attribute:"see_also", value:"http://support.apple.com/kb/HT6001");
      script_set_attribute(attribute:"see_also", value:"https://lists.apple.com/archives/security-announce/2013/Oct/msg00009.html");
      script_set_attribute(attribute:"solution", value:
    "Upgrade to Apple iTunes 11.1.2 or later.");
      script_set_cvss_base_vector("CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P");
      script_set_cvss_temporal_vector("CVSS2#E:POC/RL:OF/RC:C");
      script_set_attribute(attribute:"cvss_score_source", value:"CVE-2013-2842");
    
      script_set_attribute(attribute:"exploitability_ease", value:"Exploits are available");
      script_set_attribute(attribute:"exploit_available", value:"true");
    
      script_set_attribute(attribute:"vuln_publication_date", value:"2013/10/22");
      script_set_attribute(attribute:"patch_publication_date", value:"2013/10/22");
      script_set_attribute(attribute:"plugin_publication_date", value:"2013/10/24");
    
      script_set_attribute(attribute:"plugin_type", value:"local");
      script_set_attribute(attribute:"cpe", value:"cpe:/a:apple:itunes");
      script_end_attributes();
    
      script_category(ACT_GATHER_INFO);
      script_family(english:"Windows");
    
      script_copyright(english:"This script is Copyright (C) 2013-2019 and is owned by Tenable, Inc. or an Affiliate thereof.");
    
      script_dependencies("itunes_detect.nasl");
      script_require_keys("SMB/iTunes/Version");
    
      exit(0);
    }
    
    
    include("audit.inc");
    include("global_settings.inc");
    include("misc_func.inc");
    
    
    version = get_kb_item_or_exit("SMB/iTunes/Version");
    fixed_version = "11.1.2.31";
    path = get_kb_item_or_exit("SMB/iTunes/Path");
    
    if (ver_compare(ver:version, fix:fixed_version) == -1)
    {
      port = get_kb_item("SMB/transport");
      if (!port) port = 445;
    
      if (report_verbosity > 0)
      {
        report =
          '\n  Path              : '+path+
          '\n  Installed version : '+version+
          '\n  Fixed version     : '+fixed_version+'\n';
        security_hole(port:port, extra:report);
      }
      else security_hole(port);
    }
    else audit(AUDIT_INST_PATH_NOT_VULN, "iTunes", version, path);
    
  • NASL familyMisc.
    NASL idAPPLETV_6_0.NASL
    descriptionAccording to its banner, the remote Apple TV 2nd generation or later device is prior to 6.0. It is, therefore, reportedly affected by multiple vulnerabilities, the most serious issues of which could result in arbitrary code execution.
    last seen2020-06-01
    modified2020-06-02
    plugin id70257
    published2013-10-01
    reporterThis script is Copyright (C) 2013-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/70257
    titleApple TV < 6.0 Multiple Vulnerabilities
  • NASL familyPeer-To-Peer File Sharing
    NASL idITUNES_11_1_4_BANNER.NASL
    descriptionThe version of Apple iTunes on the remote host is prior to version 11.1.4. It is, therefore, affected by multiple vulnerabilities : - The included versions of the WebKit, libxml, and libxslt components in iTunes contain several errors that can lead to memory corruption and arbitrary code execution. The vendor states that one possible vector is a man-in- the-middle attack while the application browses the
    last seen2020-06-01
    modified2020-06-02
    plugin id72105
    published2014-01-23
    reporterThis script is Copyright (C) 2014-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/72105
    titleApple iTunes < 11.1.4 Multiple Vulnerabilities (uncredentialed check)