lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  PHC 
Open Source and information security mailing list archives
 
Hash Suite for Android: free password hash cracker in your pocket
[<prev] [next>] [day] [month] [year] [list]
Date: Mon, 25 Sep 2017 11:36:53 -0700
From: Apple Product Security <product-security-noreply@...ts.apple.com>
To: security-announce@...ts.apple.com
Subject: [FD] APPLE-SA-2017-09-25-8 iTunes 12.7 for Windows

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

APPLE-SA-2017-09-25-8 iTunes 12.7 for Windows

iTunes 12.7 for Windows addresses the following:

WebKit
Available for:  Windows 7 and later
Impact: Processing maliciously crafted web content may lead to
arbitrary code execution
Description: A memory corruption issue was addressed through improved
input validation.
CVE-2017-7081: Apple
Entry added September 25, 2017

WebKit
Available for:  Windows 7 and later
Impact: Processing maliciously crafted web content may lead to
arbitrary code execution
Description: Multiple memory corruption issues were addressed with
improved memory handling.
CVE-2017-7087: Apple
CVE-2017-7091: Wei Yuan of Baidu Security Lab working with Trend
Micro’s Zero Day Initiative
CVE-2017-7092: Qixun Zhao (@S0rryMybad) of Qihoo 360 Vulcan Team,
Samuel Gro and Niklas Baumstark working with Trend Micro's Zero Day
Initiative
CVE-2017-7093: Samuel Gro and Niklas Baumstark working with Trend
Micro’s Zero Day Initiative
CVE-2017-7094: Tim Michaud (@TimGMichaud) of Leviathan Security Group
CVE-2017-7095: Wang Junjie, Wei Lei, and Liu Yang of Nanyang
Technological University working with Trend Micro’s Zero Day
Initiative
CVE-2017-7096: Wei Yuan of Baidu Security Lab
CVE-2017-7098: Felipe Freitas of Instituto Tecnológico de Aeronáutica
CVE-2017-7099: Apple
CVE-2017-7100: Masato Kinugawa and Mario Heiderich of Cure53
CVE-2017-7102: Wang Junjie, Wei Lei, and Liu Yang of Nanyang
Technological University
CVE-2017-7104: likemeng of Baidu Secutity Lab
CVE-2017-7107: Wang Junjie, Wei Lei, and Liu Yang of Nanyang
Technological University
CVE-2017-7111: likemeng of Baidu Security Lab (xlab.baidu.com)
working with Trend Micro's Zero Day Initiative
CVE-2017-7117: lokihardt of Google Project Zero
CVE-2017-7120: chenqin (陈钦) of Ant-financial Light-Year Security
Lab
Entry added September 25, 2017

WebKit
Available for:  Windows 7 and later
Impact: Cookies belonging to one origin may be sent to another origin
Description: A permissions issue existed in the handling of web
browser cookies. This issue was addressed by no longer returning
cookies for custom URL schemes.
CVE-2017-7090: Apple
Entry added September 25, 2017

WebKit
Available for:  Windows 7 and later
Impact: Processing maliciously crafted web content may lead to a
cross site scripting attack
Description: Application Cache policy may be unexpectedly applied.
CVE-2017-7109: avlidienbrunn
Entry added September 25, 2017

Installation note:

iTunes 12.7 for Windows may be obtained from:
https://www.apple.com/itunes/download/

Information will also be posted to the Apple Security Updates
web site: https://support.apple.com/kb/HT201222

This message is signed with Apple's Product Security PGP key,
and details are available at:
https://www.apple.com/support/security/pgp/
-----BEGIN PGP SIGNATURE-----
Comment: GPGTools - https://gpgtools.org

iQIcBAEBCgAGBQJZyUQgAAoJEIOj74w0bLRGxhsP+wXSLgL1JbHxZxzEPyBIy40Q
As9yvCfyy9l1edhsjji9HWfsyV7voJMnSYu21jrfc+oiw85AhLyWAP0pqzZVaO/k
XQZQYJJ70lQj9gP9PHJxVOGJhbE7vhC/80JA2ckPGKIA5+8bWY69klh7N1Ks871Z
YrzCe32LNxtV5tCWpF60utOpbDudz5BtTS4vC5xJa6o5+M6kjhaF/AFb0FqeI8VM
hmeyABpuz+KSp7zTUEW2f2JxmTJ4pIkfMA2ttJypnA4k07j4lO7c7CHZNP6PpbCX
aoNq431BaN7UH9Bb25o5UXK/74PbSRP5WDamL99M6YvHYSmM/du0gDosXUvBxo5R
0qn+HkfR9QskfMDb3PxFo6OfZnFzHa9AjZ8cRewB+BOAyBOVMlLM4b0Rr0yhkjiG
L3TDGFpbykxYaHN096xP3J4M0MvYihSFXSkXWL9b6mwCfQuBtRU+ChI8rUecbY13
+7BY5O9l6/mNxBQh7jvR+JwP2QWNb+6ioDLjKjorw9AV17tMZTX5tuvq5+rAEoYt
u0m9arhWvjftOufHN9gaLJrjfdl9TueesydjlXtIzITBZ14vuzt1ykbZXt0kqCrJ
V8yRvaKYQKCB2hF5hrqpWmTdJ7rOu5Es9l9xZz+0C9JXPtDIpk3ayzXHc9D9+BRk
9hJGdstIhzalhaMSDyEa
=Usys
-----END PGP SIGNATURE-----


_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: http://seclists.org/fulldisclosure/

Powered by blists - more mailing lists