7.5
CVSSv2

CVE-2008-3434

Published: 01/08/2008 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Apple iTunes prior to 10.5.1 does not properly verify the authenticity of updates, which allows man-in-the-middle malicious users to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.

Vulnerable Product Search on Vulmon Subscribe to Product

apple itunes 1.1.2

apple itunes 2.0

apple itunes 4.0

apple itunes 4.0.1

apple itunes 4.9

apple itunes 5.0

apple itunes 6.0.4.2

apple itunes

apple itunes 2.0.1

apple itunes 2.0.2

apple itunes 4.1

apple itunes 4.2

apple itunes 5.0.1

apple itunes 6.0

apple itunes 1.0

apple itunes 2.0.3

apple itunes 2.0.4

apple itunes 4.5

apple itunes 4.6

apple itunes 6.0.1

apple itunes 6.0.2

apple itunes 1.1

apple itunes 1.1.1

apple itunes 3.0

apple itunes 3.0.1

apple itunes 4.7

apple itunes 4.7.1

apple itunes 4.8

apple itunes 6.0.3

apple itunes 6.0.4