CVE-2005-0043: Buffer Overflow
Published Jan 19, 2005
·Updated
Buffer overflow in Apple iTunes 4.7 allows remote attackers to execute arbitrary code via a long URL in (1) .m3u or (2) .pls playlist files.
Affected Software
1 affected component
Apple iTunes=4.7
Remediation
Patch Available
Event History
Jan 19, 2005
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What must an attacker provide to exploit this issue?
An attacker must cause iTunes to process a malicious .m3u or .pls playlist containing an overly long URL. The vulnerability is remotely exploitable without authentication.
2
What is the potential impact if exploitation succeeds?
Successful exploitation can allow execution of arbitrary code. The reported impact includes compromise of confidentiality, integrity, and availability.
3
What should organizations do if they use affected iTunes installations?
Apply the available patch. Until patching is complete, avoid opening untrusted .m3u and .pls playlist files, particularly playlists received from external sources.