[Advisory] $ x Thu Mar 16 14:02:04 EST 2006 x $ Buffer Overflow in Apple iTunes ------------------------------------------------------ 8===D DESCRIPTION ------------------------------------------------------ It is possible to make Apple iTunes crash or run arbitrary code by the use of malformed input. ------------------------------------------------------ 8===D VENDOR RESPONSE ------------------------------------------------------ Apple iTunes has extended no information regarding the vulnerability in question. ------------------------------------------------------ 8===D CVE INFORMATION ------------------------------------------------------ The Common Vulnerabilities and Exposures (CVE) project has assigned the name CVE-2006-105072 to this issue ------------------------------------------------------ APPENDIX A VENDOR INFORMATION ------------------------------------------------------ http://www.apple.com/itunes/ ------------------------------------------------------ CONTACT ------------------------------------------------------ Pavel Kankovsky [EMAIL PROTECTED] CISSP CCE CEH CSFA GREM SSP-CNSA SSP-MPA GWAS CAP SSCP _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/