CVE-2009-0950
Apple iTunes < 8.2 - Remote Code Execution via Long itms: URL Component
Title source: llmExploitation Summary
EIP tracks 5 public exploits for CVE-2009-0950.
PoCs published by Metasploit, Simo36, ryujin, including Metasploit module exploits/multi/browser/itms_overflow.
AI-analyzed exploit summary This exploit targets a stack-based buffer overflow in iTunes 8.1.1 via maliciously crafted itms:// URLs. It leverages JavaScript to trigger the vulnerability, leading to remote code execution on macOS systems.
Description
Stack-based buffer overflow in Apple iTunes before 8.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an itms: URL with a long URL component after a colon.
Exploits (5)
This exploit targets a stack-based buffer overflow in iTunes 8.1.1 via maliciously crafted itms:// URLs. It leverages JavaScript to trigger the vulnerability, leading to remote code execution on macOS systems.
This exploit targets a buffer overflow vulnerability in Apple iTunes 8.1.x (CVE-2009-0950) via the DAAP protocol. It uses a crafted URL to trigger the overflow and execute shellcode, resulting in remote code execution.
This exploit targets a buffer overflow vulnerability in Apple iTunes 8.1.1.10 via crafted itms/itpc URIs, bypassing stack canary protection by overwriting SEH. It delivers an Alpha2-encoded ASCII shellcode to achieve remote code execution on Windows XP.
This exploit targets a stack-based buffer overflow in iTunes 8.1.1 via malformed itms:// URLs, allowing remote code execution when a user visits a crafted webpage. The payload is delivered through an HTML page with embedded JavaScript that triggers the vulnerability.
This Metasploit module exploits a stack-based buffer overflow in iTunes 8.1.1 via maliciously crafted itms:// URLs, allowing remote code execution when visited in Safari. The payload is delivered through an HTML page with a meta-refresh or direct link.