CVE-2012-3607: Buffer Overflow
WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-3607?
CVE-2012-3607 is classified as high severity due to its potential to allow remote code execution and application crashes.
How do I fix CVE-2012-3607?
To fix CVE-2012-3607, update Apple iTunes to version 10.7 or later as it addresses this vulnerability.
What platforms are affected by CVE-2012-3607?
CVE-2012-3607 affects Apple iTunes versions 10.6.3 and earlier on macOS and Windows platforms.
What type of vulnerability is CVE-2012-3607?
CVE-2012-3607 is a memory corruption vulnerability in WebKit, allowing for arbitrary code execution.
Can CVE-2012-3607 be exploited through a web page?
Yes, CVE-2012-3607 can be exploited by attackers via a crafted web page that targets the vulnerable versions of iTunes.