CVE-2014-1242: Medium severity Apple iTunes vulnerability
Published Jan 23, 2014
·Updated
Apple iTunes before 11.1.4 uses HTTP for the iTunes Tutorials window, which allows man-in-the-middle attackers to spoof content by gaining control over the client-server data stream.
Affected Software
10 affected components
Apple iTunes<=11.1.3
Apple iTunes=11.0
Apple iTunes=11.0.1
Apple iTunes=11.0.2
Apple iTunes=11.0.3
Apple iTunes=11.0.4
Apple iTunes=11.0.5
Apple iTunes=11.1
Apple iTunes=11.1.1
Apple iTunes=11.1.2
Event History
Jan 23, 2014
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Data Sourced
via NVD·07:55 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-1242?
CVE-2014-1242 is considered to have a medium severity level due to the potential for man-in-the-middle attacks.
2
How do I fix CVE-2014-1242?
To fix CVE-2014-1242, upgrade to Apple iTunes version 11.1.4 or later.
3
Who is affected by CVE-2014-1242?
CVE-2014-1242 affects users of Apple iTunes versions up to 11.1.3.
4
What type of attack does CVE-2014-1242 allow?
CVE-2014-1242 allows man-in-the-middle attackers to spoof content by intercepting the client-server data stream.
5
When was CVE-2014-1242 published?
CVE-2014-1242 was published in January 2014.