JAN 14: Apple Fixes iTunes Security Flaw - BX's Silicon Valley (Computers, Technology) - Boxden Articles




http://www.boxden.com


A diverse, large, and expanding unique urban community that blog and discuss various aspects of life as the young adult. From music, movie, and video game reviews and discussions, to computers, fitness/health, and latest fashion trends. Its all here, and we are constantly expanding with over 100 new members joining daily!

[Free all expense paid membership to BX] 


PDA

View Full Version : JAN 14: Apple Fixes iTunes Security Flaw


EASTLondon
01-14-2005, 05:23 AM
By Matthew Broersma

eweek.com

Along with introducing a slew of new hardware and software on Tuesday, Apple Computer Inc. also quietly released an update for iTunes that fixes a serious security vulnerability found in both Windows and Mac OS X versions of the media player.

The update, iTunes 4.7.1, patches a bug in the way iTunes handles the common .m3u and .pls playlist files. A buffer overflow that occurs when a user attempts to play one of these files—often exchanged over the Internet as a way of organizing music tracks—can crash the player and execute malicious code on a user's system, company officials said.

The vulnerability, which merited a "highly critical (http://secunia.com/advisories/13804/)" rating from independent security research firm Secunia, affects Windows XP, Windows 2000 and Mac OS X systems. Apple security information and updates can be found on Apple's Web site (http://docs.info.apple.com/article.html?artnum=61798).

Besides the security fix, iTunes 4.7.1 also adds shuffle and photo features for the iPod, as well as performance improvements.

News Article Link (http://www.eweek.com/article2/0,1759,1750634,00.asp)