First published: Wed Sep 10 2008(Updated: )
Apple iTunes before 8.0 on Mac OS X 10.4.11, when iTunes Music Sharing is enabled but blocked by the host-based firewall, presents misleading information about firewall security, which might allow remote attackers to leverage an exposure that would be absent if the administrator were given better information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
macOS Yosemite | =10.4.11 | |
Apple Mac OS X Server | =10.4.11 | |
Apple iTunes | ||
Apple iTunes | <=7.7.1 | |
Apple iTunes | =1.0 | |
Apple iTunes | =1.1 | |
Apple iTunes | =1.1.1 | |
Apple iTunes | =1.1.2 | |
Apple iTunes | =2.0 | |
Apple iTunes | =2.0.1 | |
Apple iTunes | =2.0.2 | |
Apple iTunes | =2.0.3 | |
Apple iTunes | =2.0.4 | |
Apple iTunes | =3.0 | |
Apple iTunes | =3.0.1 | |
Apple iTunes | =4.0 | |
Apple iTunes | =4.0.1 | |
Apple iTunes | =4.1 | |
Apple iTunes | =4.2 | |
Apple iTunes | =4.2.72 | |
Apple iTunes | =4.5 | |
Apple iTunes | =4.6 | |
Apple iTunes | =4.7 | |
Apple iTunes | =4.7.1 | |
Apple iTunes | =4.7.1.30 | |
Apple iTunes | =4.8 | |
Apple iTunes | =4.9 | |
Apple iTunes | =5.0 | |
Apple iTunes | =5.0.1 | |
Apple iTunes | =6.0 | |
Apple iTunes | =6.0.1 | |
Apple iTunes | =6.0.2 | |
Apple iTunes | =6.0.3 | |
Apple iTunes | =6.0.4 | |
Apple iTunes | =6.0.4.2 | |
Apple iTunes | =6.0.5 | |
Apple iTunes | =7.0.2 | |
Apple iTunes | =7.3.2 | |
Apple iTunes | =7.4 | |
Apple iTunes | =7.4.1 | |
Apple iTunes | =7.4.2 | |
Apple iTunes | =7.4.3 | |
Apple iTunes | =7.5 | |
Apple iTunes | =7.6 | |
Apple iTunes | =7.6.1 | |
Apple iTunes | =7.6.2 | |
Apple iTunes | =7.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2008-3634 is considered to be moderate due to its potential to mislead users about firewall security.
To fix CVE-2008-3634, users should upgrade to iTunes version 8.0 or later, which addresses the vulnerability.
CVE-2008-3634 affects iTunes versions 7.7 and earlier running on Mac OS X 10.4.11.
Yes, CVE-2008-3634 could potentially be exploited remotely if the conditions of the firewall misconfiguration exist.
CVE-2008-3634 indicates that misleading information about firewall settings can create vulnerabilities in network security.