CVE-2012-3606: Buffer Overflow
WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-3606?
The severity of CVE-2012-3606 is considered to be high as it allows remote code execution and potential denial of service.
How do I fix CVE-2012-3606?
To fix CVE-2012-3606, update Apple iTunes to the latest version available since versions prior to 10.7 are affected.
Which versions of iTunes are affected by CVE-2012-3606?
CVE-2012-3606 affects Apple iTunes versions before 10.7, including various specific versions of 4.x through 10.6.
What kind of attacks can CVE-2012-3606 facilitate?
CVE-2012-3606 can facilitate remote code execution attacks as well as cause memory corruption leading to application crashes.
Is CVE-2012-3606 specific to any operating system?
CVE-2012-3606 affects iTunes on both macOS and Windows platforms.