CVE-2011-0170: Buffer Overflow
Heap-based buffer overflow in ImageIO in CoreGraphics in Apple iTunes before 10.2 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted International Color Consortium (ICC) profile in a JPEG image.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2011-0170?
CVE-2011-0170 is considered a critical severity vulnerability due to the potential for remote code execution.
How do I fix CVE-2011-0170?
To fix CVE-2011-0170, update Apple iTunes to version 10.2 or later on Windows.
What is the impact of CVE-2011-0170?
The impact of CVE-2011-0170 includes the possibility of arbitrary code execution or a denial of service through application crashes.
Which versions of iTunes are affected by CVE-2011-0170?
CVE-2011-0170 affects all versions of Apple iTunes prior to 10.2 on Windows.
Can CVE-2011-0170 exploit my system remotely?
Yes, CVE-2011-0170 allows remote attackers to exploit the vulnerability through specially crafted JPEG images.