CVE-2013-0991: Medium severity Apple iTunes vulnerability
WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0991?
CVE-2013-0991 has been classified as a high severity vulnerability due to its potential for arbitrary code execution and denial of service.
How do I fix CVE-2013-0991?
To mitigate CVE-2013-0991, update Apple iTunes to version 11.0.3 or later.
Which versions of Apple iTunes are affected by CVE-2013-0991?
CVE-2013-0991 affects Apple iTunes versions prior to 11.0.3.
Can CVE-2013-0991 be exploited remotely?
Yes, CVE-2013-0991 can be exploited remotely by man-in-the-middle attackers.
What types of attacks can CVE-2013-0991 facilitate?
CVE-2013-0991 can facilitate arbitrary code execution or cause memory corruption leading to application crashes.