Advertisement
Promo

Security threats Toolkit

iTunes update fixes security flaw

Andrew Donoghue ZDNet.co.uk

Published: 24 Sep 2009 14:48 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Apple has issued an update to its iTunes music software, patching a security flaw that could open Mac or Windows machines to attack.

Announced on Tuesday, iTunes 9.0.1 arrives two weeks after iTunes 9.0, which was released on 9 September. It cleans up a buffer overflow flaw could allow an attacker to create a malicious playlist file that, if clicked on, could let the intruder crash applications or remotely run code on the computer, possibly taking it over.

"Opening a maliciously crafted .pls file may lead to an unexpected application termination or arbitrary code execution," Apple said in its security advisory.

The security patch is available for machines running Mac OS X v10.4.11 or later, Mac OS X Server v10.4.11 or later, plus Windows XP, Vista and Windows 7.

As well as patching the security flaw, iTunes 9.0.1 includes fixes for other bugs, such as the music player becoming unresponsive or unexpectedly quitting. It also improves application syncing and the browsing in the iTunes store, according to Apple.

iTunes 9 featured new functionality such as home sharing, which allows contents to be shared across a home network; more use of cover art to ease navigation; and a redesigned iTunes Store.

In August, Apple patched an arbitrary code execution flaw in the iPhone which could have allowed a hacker to control the device by sending an SMS.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
5 out of 9 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:








Video icon

Video

Sentry Posts Blog

Climate research centre compromised

One of the UK's leading climate change research centres has had a security breach. The Climate Research Unit at the University of East Anglia (UEA) suffered a compromise of information,... More

1 comment

Government web-monitoring plans on hol...

Government plans to compel ISPs to process and store details of all web communications have been put on hold until after the next election. The Home Office told ZDNet UK on Wednesday... More

1 comment

Watchdog reveals illegal sale of phone...

The Information Commissioner's Office is preparing a prosecution file against a mobile operator's employees who allegedly sold on thousands of customers' details to a competitor. The... More

1 comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters