33742vdb entry
http://osvdb.org/33742 CVE-2007-1008
Apple iTunes 7.0.2 - XML Parsing Remote Denial of Service
Record summary
CVE-2007-1008 has a selected CVSS score of 2.6; EIP currently links 1 catalogued exploit.
Description
Apple iTunes 7.0.2 allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted XML list of radio stations, which results in memory corruption. NOTE: iTunes retrieves the XML document from a static URL, which requires an attacker to perform DNS spoofing or man-in-the-middle attacks for exploitation.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBApple iTunes 7.0.2 - XML Parsing Remote Denial of ServiceExploitDB exploitby poplixNot analyzed1 file
References
62278Third-party advisory
http://securityreason.com/securityalert/2278 20070219 iTunes remote memory corruption vulnerabilitymailing list
http://www.securityfocus.com/archive/1/460544/100/0/threaded 22615vdb entry
http://www.securityfocus.com/bid/22615 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2007-1008 oval:org.mitre.oval:def:16978vdb entrysignature
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16978