First published: Thu Sep 13 2012(Updated: )
WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
iTunes | <=10.6.3 | |
iTunes | =4.0.0 | |
iTunes | =4.0.0 | |
iTunes | =4.0.1 | |
iTunes | =4.0.1 | |
iTunes | =4.1.0 | |
iTunes | =4.1.0 | |
iTunes | =4.2.0 | |
iTunes | =4.2.0 | |
iTunes | =4.5 | |
iTunes | =4.5 | |
iTunes | =4.5.0 | |
iTunes | =4.5.0 | |
iTunes | =4.6 | |
iTunes | =4.6 | |
iTunes | =4.6.0 | |
iTunes | =4.6.0 | |
iTunes | =4.7 | |
iTunes | =4.7 | |
iTunes | =4.7.0 | |
iTunes | =4.7.0 | |
iTunes | =4.7.1 | |
iTunes | =4.7.1 | |
iTunes | =4.7.1 | |
iTunes | =4.7.2 | |
iTunes | =4.8.0 | |
iTunes | =4.8.0 | |
iTunes | =4.9.0 | |
iTunes | =4.9.0 | |
iTunes | =5.0 | |
iTunes | =5.0 | |
iTunes | =5.0.0 | |
iTunes | =5.0.0 | |
iTunes | =5.0.1 | |
iTunes | =5.0.1 | |
iTunes | =6.0.0 | |
iTunes | =6.0.0 | |
iTunes | =6.0.1 | |
iTunes | =6.0.1 | |
iTunes | =6.0.1 | |
iTunes | =6.0.2 | |
iTunes | =6.0.2 | |
iTunes | =6.0.2 | |
iTunes | =6.0.3 | |
iTunes | =6.0.3 | |
iTunes | =6.0.4 | |
iTunes | =6.0.4 | |
iTunes | =6.0.4 | |
iTunes | =6.0.5 | |
iTunes | =6.0.5 | |
iTunes | =7.0.0 | |
iTunes | =7.0.0 | |
iTunes | =7.0.1 | |
iTunes | =7.0.1 | |
iTunes | =7.0.2 | |
iTunes | =7.0.2 | |
iTunes | =7.0.2 | |
iTunes | =7.1.0 | |
iTunes | =7.1.0 | |
iTunes | =7.1.1 | |
iTunes | =7.1.1 | |
iTunes | =7.2.0 | |
iTunes | =7.2.0 | |
iTunes | =7.3.0 | |
iTunes | =7.3.0 | |
iTunes | =7.3.1 | |
iTunes | =7.3.1 | |
iTunes | =7.3.2 | |
iTunes | =7.3.2 | |
iTunes | =7.3.2 | |
iTunes | =7.4 | |
iTunes | =7.4 | |
iTunes | =7.4.0 | |
iTunes | =7.4.0 | |
iTunes | =7.4.1 | |
iTunes | =7.4.1 | |
iTunes | =7.4.1 | |
iTunes | =7.4.2 | |
iTunes | =7.4.2 | |
iTunes | =7.4.2 | |
iTunes | =7.4.3 | |
iTunes | =7.4.3 | |
iTunes | =7.5 | |
iTunes | =7.5 | |
iTunes | =7.5.0 | |
iTunes | =7.5.0 | |
iTunes | =7.6 | |
iTunes | =7.6.0 | |
iTunes | =7.6.0 | |
iTunes | =7.6.1 | |
iTunes | =7.6.1 | |
iTunes | =7.6.1 | |
iTunes | =7.6.2 | |
iTunes | =7.6.2 | |
iTunes | =7.7 | |
iTunes | =7.7.0 | |
iTunes | =7.7.0 | |
iTunes | =7.7.1 | |
iTunes | =7.7.1 | |
iTunes | =7.7.1 | |
iTunes | =8.0.0 | |
iTunes | =8.0.0 | |
iTunes | =8.0.1 | |
iTunes | =8.0.1 | |
iTunes | =9.0.0 | |
iTunes | =9.0.1 | |
iTunes | =9.0.2 | |
iTunes | =9.0.3 | |
iTunes | =9.1 | |
iTunes | =9.1.1 | |
iTunes | =9.2 | |
iTunes | =9.2.1 | |
iTunes | =10.0 | |
iTunes | =10.0.1 | |
iTunes | =10.1 | |
iTunes | =10.1.1 | |
iTunes | =10.1.1.4 | |
iTunes | =10.1.2 | |
iTunes | =10.2 | |
iTunes | =10.2.2.12 | |
iTunes | =10.3 | |
iTunes | =10.3.1 | |
iTunes | =10.4 | |
iTunes | =10.4.0.80 | |
iTunes | =10.4.1 | |
iTunes | =10.4.1.10 | |
iTunes | =10.5 | |
iTunes | =10.5.1 | |
iTunes | =10.5.1.42 | |
iTunes | =10.5.2 | |
iTunes | =10.5.3 | |
iTunes | =10.6 | |
iTunes | =10.6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-3623 is classified as a critical vulnerability due to its ability to allow remote code execution and potential denial of service.
To fix CVE-2012-3623, update to the latest version of Apple iTunes that addresses this vulnerability.
CVE-2012-3623 affects Apple iTunes versions prior to 10.7 and specific lower versions listed in the CVE report.
Exploiting CVE-2012-3623 can lead to arbitrary code execution, memory corruption, or application crashes.
While specific exploit details are not provided, the vulnerability enables remote attackers to execute arbitrary code, which increases risk.