New iTunes flaw warning

By
Follow google news

Music downloaders are being warned about an exploitable flaw in Apple’s iTunes program.

Calling the warning's severity "high," eEye warned last week that a flaw exists in the popular music downloading program that could allow malicious code to compromise it.


"A remotely exploitable flaw exists that allows arbitrary code to be executed in the context of the logged-in user," the security firm warned on its website. The vulnerability exists on all Microsoft operating systems.

Earlier last week, Apple had released an advisory that a malicious user could compromise PCs through iTunes 5 and said the vulnerability had been addressed in later versions of the program.

"Due to the way iTunes 5 for Windows launches its helper application, multiple system paths are searched to determine which program to run," Apple warned on its iTunes site. "This may allow a malicious user on the local system to create an environment where an alternate program will be executed by iTunes. This has already been addressed in the iTunes 6 release for Windows."

www.eeye.com
Learn more   →">Partner Content Cyber Engineering launches at ctrl:cyber with former Shelde founders

Empowering Sustainability: Schneider Electric's Commitment to Driving Customer Success
Empowering Sustainability: Schneider Electric's Commitment to Driving Customer Success
Suntory Oceania’s $30 million IT transformation powers carbon-neutral multi beverage facility
Suntory Oceania’s $30 million IT transformation powers carbon-neutral multi beverage facility
Machine identity a key priority for organisations’ security strategies: CyberArk
Machine identity a key priority for organisations’ security strategies: CyberArk

Most Read Articles

Telstra used ConnectID impermissibly for months

Telstra used ConnectID impermissibly for months

University of Sydney "online IT code library" breached

University of Sydney "online IT code library" breached

NSW Health clinicians "normalise" bypass of cyber security controls

NSW Health clinicians "normalise" bypass of cyber security controls

UK government was hacked in October, minister confirms

UK government was hacked in October, minister confirms

Log In

  |  Forgot your password?