lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
Message-id: <9FAC210A-1D28-48D3-8530-E9C1F0C214CF@lists.apple.com>
Date: Thu, 15 May 2014 14:07:39 -0700
From: Apple Product Security <product-security-noreply@...ts.apple.com>
To: security-announce@...ts.apple.com
Subject: APPLE-SA-2014-05-15-2 iTunes 11.2

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

APPLE-SA-2014-05-15-2 iTunes 11.2

iTunes 11.2 is now available and addresses the following:

iTunes
Available for:  Windows 8, Windows 7, Vista, XP SP3 or later
Impact:  An attacker in a privileged network position can obtain
iTunes credentials
Description:  Set-Cookie HTTP headers would be processed even if the
connection closed before the header line was complete. An attacker
could strip security settings from the cookie by forcing the
connection to close before the security settings were sent, and then
obtain the value of the unprotected cookie. This issue was addressed
by ignoring incomplete HTTP header lines.
CVE-ID
CVE-2014-1296

iTunes 11.2 may be obtained from:
http://www.apple.com/itunes/download/

For Windows XP / Vista / Windows 7 / Windows 8:
The download file is named: "iTunesSetup.exe"
Its SHA-1 digest is: 0e96aec6ba9959fd288e662b4fcbe58fd2bb89eb

For 64-bit Windows XP / Vista / Windows 7 / Windows 8:
The download file is named: "iTunes64Setup.exe"
Its SHA-1 digest is: eb7da1d648c41a5b1e3ccc00ca26dcaa1f6d04d5

Information will also be posted to the Apple Security Updates
web site: http://support.apple.com/kb/HT1222

This message is signed with Apple's Product Security PGP key,
and details are available at:
https://www.apple.com/support/security/pgp/

-----BEGIN PGP SIGNATURE-----
Version: GnuPG/MacGPG2 v2.0.22 (Darwin)
Comment: GPGTools - http://gpgtools.org

iQIcBAEBAgAGBQJTdSj9AAoJEBcWfLTuOo7tmnoP/i5B4nL/Al9kdEQHN+EhaVl5
i406n6dVtfo/MdBz2jB99wkAsEQp2xNqBs2Bw1nEB9InPo4w/Jy6LkPR5VR9E+c/
HAn9TnN0yUGu6KNfm02G+8qWoMfCL+aHhL8uEN8/0ljjv2Wirf4SykmoLTxcpC7x
6Z4ABeNhQfRpIZVHsmLSNZ1WrpChs74ycPkM9dgI5jNe6gC3W3sFrPK63I8fwiIU
I1Qfb89C6u7b0Csmd1jhAss+0fXkiR6k7VsZEsIeS1yJtIV1mFFULPAOd2MYcLTU
64u6dHWgMHcjLkIDKqzWjyCjlFZ6/H5hMnxVLuNnh/pKbcSUd/naSAsRldc6vXE6
S/wyjAPisyWZ5bsi6KZSJmaAScBMoMQXak1HcaCJEwKqREiyUoBGI6m2Z21IN8AX
L1ymTwFWY/K4VyrsR+CpBtxukLIKQWUwQADCfSGEgTSF4wYeRQVjknAtMJXuqZi2
8AGamj3Cl2tWHvi3rWRjoQSKb2ZTuFmkWkXf5OUa7UWa6qEnV9pZdAdqomVXNRsR
vGllQT+iQvAccHyXR5+jiCatSzd6N70iXejYo4jFsMlksYe5gltbYPu3bPFgqXmP
t2+fISgNB4mNx11iy2qwqbQC2NVeguqjD5V/u1wXSJ/Pl774xHrmL9F4evwY7Fla
+RyBNGTKqHzsoL+ucr3i
=ehLN
-----END PGP SIGNATURE-----


Download attachment "signature.asc" of type "application/pgp-signature" (842 bytes)

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ