CVE-2005-2938: High severity Apple iTunes vulnerability
Published Nov 18, 2005
·Updated
Unquoted Windows search path vulnerability in iTunesHelper.exe in iTunes 4.7.1.30 and iTunes 5 for Windows might allow local users to gain privileges via a malicious C:\program.exe file.
Affected Software
2 affected components
Apple iTunes=4.7.1.30
Apple iTunes=5.0
Event History
Nov 18, 2005
CVE Published
06:03 AM
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-2938?
CVE-2005-2938 has a medium severity rating due to its potential to allow local users to gain elevated privileges.
2
How do I fix CVE-2005-2938?
To mitigate CVE-2005-2938, ensure that iTunes is updated to a version that no longer contains the unquoted search path vulnerability.
3
What software versions are affected by CVE-2005-2938?
CVE-2005-2938 affects iTunes versions 4.7.1.30 and 5.0 for Windows.
4
What type of vulnerability is CVE-2005-2938?
CVE-2005-2938 is classified as an unquoted Windows search path vulnerability.
5
Can CVE-2005-2938 be exploited remotely?
CVE-2005-2938 is a local vulnerability, meaning it requires access to the affected system to exploit.