CVE-2011-3252: Buffer Overflow
Buffer overflow in CoreAudio, as used in Apple iTunes before 10.5, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Advanced Audio Coding (AAC) stream.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2011-3252?
CVE-2011-3252 is considered critical due to its potential to allow remote attackers to execute arbitrary code or cause a denial of service.
How do I fix CVE-2011-3252?
The vulnerability can be fixed by updating Apple iTunes to version 10.5 or later.
What versions of Apple iTunes are affected by CVE-2011-3252?
CVE-2011-3252 affects Apple iTunes versions prior to 10.5, including versions 4.0.0 through 10.4.
What kind of attack does CVE-2011-3252 facilitate?
CVE-2011-3252 facilitates attacks via crafted Advanced Audio Coding (AAC) streams, leading to buffer overflow conditions.
How can I identify if my system is vulnerable to CVE-2011-3252?
You can identify vulnerability to CVE-2011-3252 by checking if your Apple iTunes version is below 10.5.