lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
Message-Id: <200903130154.n2D1sdFY018968@smtp.fortinet.com>
Date: Fri, 13 Mar 2009 09:59:57 +0800
From: "secresearch@...tinet.com"<secresearch@...tinet.com>
To: "full-disclosure" <full-disclosure@...ts.grok.org.uk>,
	"bugtraq" <bugtraq@...urityfocus.com>
Subject: Apple iTunes DAAP Messages Handling Denial of
	Service Vulnerability 

Apple iTunes DAAP Messages Handling Denial of Service Vulnerability . . 
2009.Mar.13 . 

Fortinet's FortiGuard Global Security Research Team Discovers Vulnerability in Apple iTunes.

Summary: . 
========. 
    A DoS vulnerability in Apple iTunes through a maliciously crafted DAAP message.. 
    
Impact:. 
.=======
 
    Denial of service.. 
. 
Risk: . 
=====

    Medium . 
. 
Affected Software: . 
.==================
 
    Apple iTunes 8 for Windows, other versions may be affected. . 
    This issue does not affect Mac OS X systems. 

References: . 
===========
. 
	FortiGuard Advisory:     http://www.fortiguardcenter.com/advisory/FGA-2009-11.html
    Apple Security Bulletin: http://support.apple.com/kb/HT3487 . 
    Apple Security Updates:  http://support.apple.com/kb/ht1222 . 
    CVE ID: CVE-2009-0016 .   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0016
. 
Acknowledgments: . . 
.================
 
    Xiaopeng Zhang, Zhenhua Liu, and Junfeng Jia of Fortinet's FortiGuard Global Security Research Team. 


*** This email and any attachments thereto may contain private, confidential, and privileged material for the sole use of the intended recipient.  Any review, copying, or distribution of this email (or any attachments thereto) by others is strictly prohibited.  If you are not the intended recipient, please contact the sender immediately and permanently delete the original and any copies of this email and any attachments thereto. ***


_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ