First published: Wed Oct 12 2011(Updated: )
Buffer overflow in CoreMedia, as used in Apple iTunes before 10.5, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with H.264 encoding.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iTunes | <=10.4.1 | |
Apple iTunes | =4.0.0 | |
Apple iTunes | =4.0.1 | |
Apple iTunes | =4.1.0 | |
Apple iTunes | =4.2.0 | |
Apple iTunes | =4.5 | |
Apple iTunes | =4.5.0 | |
Apple iTunes | =4.6 | |
Apple iTunes | =4.6.0 | |
Apple iTunes | =4.7 | |
Apple iTunes | =4.7.0 | |
Apple iTunes | =4.7.1 | |
Apple iTunes | =4.7.2 | |
Apple iTunes | =4.8.0 | |
Apple iTunes | =4.9.0 | |
Apple iTunes | =5.0 | |
Apple iTunes | =5.0.0 | |
Apple iTunes | =5.0.1 | |
Apple iTunes | =6.0.0 | |
Apple iTunes | =6.0.1 | |
Apple iTunes | =6.0.2 | |
Apple iTunes | =6.0.3 | |
Apple iTunes | =6.0.4 | |
Apple iTunes | =6.0.4.2 | |
Apple iTunes | =6.0.5 | |
Apple iTunes | =7.0.0 | |
Apple iTunes | =7.0.1 | |
Apple iTunes | =7.0.2 | |
Apple iTunes | =7.1.0 | |
Apple iTunes | =7.1.1 | |
Apple iTunes | =7.2.0 | |
Apple iTunes | =7.3.0 | |
Apple iTunes | =7.3.1 | |
Apple iTunes | =7.3.2 | |
Apple iTunes | =7.4 | |
Apple iTunes | =7.4.0 | |
Apple iTunes | =7.4.1 | |
Apple iTunes | =7.4.2 | |
Apple iTunes | =7.4.3 | |
Apple iTunes | =7.5 | |
Apple iTunes | =7.5.0 | |
Apple iTunes | =7.6 | |
Apple iTunes | =7.6.0 | |
Apple iTunes | =7.6.1 | |
Apple iTunes | =7.6.2 | |
Apple iTunes | =7.7 | |
Apple iTunes | =7.7.0 | |
Apple iTunes | =7.7.1 | |
Apple iTunes | =8.0.0 | |
Apple iTunes | =8.0.1 | |
Apple iTunes | =8.0.2 | |
Apple iTunes | =8.1 | |
Apple iTunes | =8.1.1 | |
Apple iTunes | =8.2 | |
Apple iTunes | =8.2.1 | |
Apple iTunes | =9.0.0 | |
Apple iTunes | =9.0.1 | |
Apple iTunes | =9.0.2 | |
Apple iTunes | =9.0.3 | |
Apple iTunes | =9.2 | |
Apple iTunes | =9.2.1 | |
Apple iTunes | =10.0 | |
Apple iTunes | =10.0.1 | |
Apple iTunes | =10.1 | |
Apple iTunes | =10.1.1 | |
Apple iTunes | =10.1.2 | |
Apple iTunes | =10.2 | |
Apple iTunes | =10.3 | |
Apple iTunes | =10.3.1 | |
Apple iTunes | =10.4 | |
Microsoft Windows 7 | ||
Microsoft Windows Vista | ||
Microsoft Windows Vista | =sp1 | |
Microsoft Windows Vista | =sp2 | |
Microsoft Windows XP | =sp2 | |
Microsoft Windows XP | =sp3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2011-3219 is critical due to its potential for remote code execution and denial of service via a malformed H.264 movie file.
To fix CVE-2011-3219, update Apple iTunes to version 10.5 or later.
Affected versions for CVE-2011-3219 include all versions of Apple iTunes prior to 10.5.
CVE-2011-3219 can be exploited by remote attackers through specially crafted H.264 movie files.
If unable to update iTunes, users should avoid opening untrusted movie files to mitigate risks associated with CVE-2011-3219.