CVE-2011-0115: Buffer Overflow
The DOM level 2 implementation in WebKit, as used in Apple iTunes before 10.2 on Windows and Apple Safari, does not properly handle DOM manipulations associated with event listeners during processing of range objects, which allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2011-0115?
CVE-2011-0115 has a severity rating that indicates a risk of remote code execution or denial of service due to improper DOM manipulation.
How do I fix CVE-2011-0115?
To fix CVE-2011-0115, ensure you update Apple iTunes or Safari to the latest version as specified by Apple.
Which versions of software are affected by CVE-2011-0115?
CVE-2011-0115 affects various versions of Apple iTunes up to 10.1.2, and prior versions of Apple Safari and WebKit.
What type of vulnerability is CVE-2011-0115?
CVE-2011-0115 is a vulnerabilities related to DOM manipulation that can allow remote code execution.
Can I still use my affected software if I have CVE-2011-0115?
Using affected software without applying the necessary updates poses a security risk, and it is recommended to update to mitigate vulnerabilities.