9.3
CVSSv2

CVE-2009-2817

Published: 24/09/2009 Updated: 19/09/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 940
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Buffer overflow in Apple iTunes prior to 9.0.1 allows remote malicious users to execute arbitrary code or cause a denial of service (application crash) via a crafted .pls file.

Vulnerable Product Search on Vulmon Subscribe to Product

apple itunes 2.0.3

apple itunes 2.0.2

apple itunes 4.0.1

apple itunes 4.5.0

apple itunes 4.1.0

apple itunes 4.7.0

apple itunes 6.0.4

apple itunes 6.0.3

apple itunes 7.3.2

apple itunes 7.1.1

apple itunes 7.6.2

apple itunes 7.7.0

apple itunes 1.1.2

apple itunes 3.0.1

apple itunes 4.2.72

apple itunes 4.6.0

apple itunes 4.7

apple itunes 6.0.2

apple itunes 6.0.4.2

apple itunes 7.0.2

apple itunes 7.3.1

apple itunes 7.5.0

apple itunes 7.4

apple itunes 7.4.2

apple itunes 7.4.1

apple itunes 7.6

apple itunes 7.7.1

apple itunes 8.2.1

apple itunes 8.2

apple itunes 1.1.1

apple itunes 4.0.0

apple itunes 5.0.1

apple itunes 4.2.0

apple itunes 4.8.0

apple itunes 7.0.0

apple itunes 7.3.0

apple itunes 8.0.2

apple itunes 8.0

apple itunes 1.0

apple itunes 2.0.4

apple itunes 2.0

apple itunes 4.0

apple itunes 4.1

apple itunes 4.7.1

apple itunes 6.0.1

apple itunes 6.0.5

apple itunes 6.0

apple itunes 7.4.0

apple itunes 7.2.0

apple itunes 7.6.1

apple itunes 7.5

apple itunes 7.7

apple itunes 8.1.1

apple itunes

apple itunes 8.1

apple itunes 4.9.0

apple itunes 7.6.0

apple itunes 2.0.1

apple itunes 4.9

apple itunes 4.7.1.30

apple itunes 4.8

apple itunes 5.0

apple itunes 6.0.0

apple itunes 7.4.3

apple itunes 5.0.0

apple itunes 7.0.1

apple itunes 7.1.0

apple itunes 8.0.0

apple itunes 3.0

apple itunes 4.2

apple itunes 4.5

apple itunes 4.6

apple itunes 8.0.1

Exploits

iTunes file handling local buffer overflow exploit that creates a malicious pls file Affects version 90 on Mac OS X ...
source: wwwsecurityfocuscom/bid/36478/info Apple iTunes is prone to a buffer-overflow vulnerability because the software fails to bounds-check user-supplied data before copying it into an insufficiently sized buffer An attacker can exploit this issue to execute arbitrary code within the context of the affected application Failed exploi ...
# Exploit Title: iTunes pls file handling buffer overflow # Date: 20091220 # Author: S2 Crew [Hungary] # Software Link: - # Version: 90 # Tested on: OSX 1058, Windows XP SP2
 (/GS flag, DOS) # CVE: CVE-2009-2817 # Code: #!/usr/bin/env ruby SETJMP = 0x92F04224 JMP_BUF = 0x8fe31290 STRDUP = 0x92EED110 # 8fe24459 jmp *%eax JMP_EAX = 0x8fe24 ...