CVE-2008-3434: Code Injection
Apple iTunes before 10.5.1 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-3434?
CVE-2008-3434 is considered critical due to its potential for attackers to execute arbitrary code via unauthorized updates.
How do I fix CVE-2008-3434?
To fix CVE-2008-3434, update iTunes to version 10.5.1 or later, which addresses the vulnerability.
What versions of iTunes are affected by CVE-2008-3434?
CVE-2008-3434 affects multiple versions of iTunes prior to 10.5.1, including versions as old as 1.0 up to 6.0.
Can CVE-2008-3434 be exploited remotely?
Yes, CVE-2008-3434 can be exploited remotely through man-in-the-middle attacks to deliver malicious updates.
Is CVE-2008-3434 related to software update security?
Yes, CVE-2008-3434 highlights a significant risk in software update security and authenticity verification.