First published: Thu Sep 06 2007(Updated: )
Heap-based buffer overflow in Apple iTunes before 7.4 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via crafted album cover art in the covr atom of an MP4/AAC file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iTunes for Windows | <=7.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-3752 has a high severity rating due to its potential to cause remote code execution or denial of service.
To fix CVE-2007-3752, upgrade Apple iTunes to version 7.4 or later.
CVE-2007-3752 can be exploited by attackers using crafted album cover art in MP4/AAC files.
Versions of Apple iTunes prior to 7.4, specifically up to 7.3.2, are affected by CVE-2007-3752.
CVE-2007-3752 can lead to application crashes or arbitrary code execution on affected systems.