Advertisement
Promo

Security threats Toolkit

iTunes update fixes security flaw

Andrew Donoghue ZDNet.co.uk

Published: 24 Sep 2009 14:48 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Apple has issued an update to its iTunes music software, patching a security flaw that could open Mac or Windows machines to attack.

Announced on Tuesday, iTunes 9.0.1 arrives two weeks after iTunes 9.0, which was released on 9 September. It cleans up a buffer overflow flaw could allow an attacker to create a malicious playlist file that, if clicked on, could let the intruder crash applications or remotely run code on the computer, possibly taking it over.

"Opening a maliciously crafted .pls file may lead to an unexpected application termination or arbitrary code execution," Apple said in its security advisory.

The security patch is available for machines running Mac OS X v10.4.11 or later, Mac OS X Server v10.4.11 or later, plus Windows XP, Vista and Windows 7.

As well as patching the security flaw, iTunes 9.0.1 includes fixes for other bugs, such as the music player becoming unresponsive or unexpectedly quitting. It also improves application syncing and the browsing in the iTunes store, according to Apple.

iTunes 9 featured new functionality such as home sharing, which allows contents to be shared across a home network; more use of cover art to ease navigation; and a redesigned iTunes Store.

In August, Apple patched an arbitrary code execution flaw in the iPhone which could have allowed a hacker to control the device by sending an SMS.

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
5 out of 9 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:








Video icon

Video

Sentry Posts Blog

Malicious Mobile Apps a Growing Concer...

Malicious Mobile Apps a Growing Concern Author: Eric Everson, MBA, MSIT-SE The phrase “mobile security” does not usually mean much to anyone, until of course they encounter their... More

Post a comment

Malicious Mobile Code: What You Need t...

Malicious Mobile Code: What You Need to Know. Author: Eric Everson, MBA, MSIT-SE The thought of someone hacking into your mobile phone to steal your personal data added to the growing... More

1 comment

Bletchley Park calls for operators for...

The home of World War II codebreaking has called for engineers to operate an electro-mechanical machine developed by mathematician Alan Turing. The Turing Bombe was a brute-force... More

2 comments


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters