I.T. Vibe
Latest Business Communications Gaming General Security Technology Virus  
   Member Services
Login
Register
   General Services
Contact Us
Merchandise
Toolbar
RSS Feeds
Other Formats
   Site Search
 
Advanced Search
   News Alerts
Enter your email address to receive news alerts
 
View Privacy Policy
Unsubscribe
   Information
Latest Virus Alerts
Internet Threat Level
Internet Traffic Report
   Opinion Poll
Macs - Love Them or Hate Them? Place your votes now.
Love 'em
Hate 'em
Indifferent
Reader Comments: 0
View All Polls
New critical security flaws in iTunes
Thursday, January 12, 2006 at 21:22 by Rich Kavanagh
eEye Digital Security today announced the discovery of four critical security vulnerabilities related to Apple Computer and the company's QuickTime software, as well as the download application for its iTunes music store.

These flaws have the potential to inflict serious damage, as they allow an attacker to take complete control of an affected system and execute harmful action remotely, including installing programs, viewing, changing or deleting data.

Enterprise networks are particularly vulnerable and organizations should take immediate action to identify affected machines, as the likelihood that the immensely popular QuickTime and iTunes applications are installed on their network is extremely high. To give an indication of the scope of this issue, the iTunes music download service has distributed 850 million songs since its introduction and is often used in conjunction with the equally popular iPod personal music system, of which 42 million have been sold since the device's inception.

Marc Maiffret, eEye's co-founder and chief hacking officer said,

"Most IT departments probably saw Apple's security update and thought ‘that's a consumer application, I don't have to worry about security policies for that.' Those IT departments would be mistaken. There are few people that have not seen a co-worker with an iPod wandering the halls of their organization and those iPods probably mean iTunes is on your network. These flaws highlight the need for rigorous security policies and their enforcement via network security scanning and comprehensive endpoint security that will allow enterprises to mitigate this growing threat."

Although these security flaws were initially found in the QuickTime application, because the popular iTunes application is so closely integrated with QuickTime, all of these security issues are also exploitable via the iTunes software. All systems running Windows 2000, Windows XP and Apple Mac OS X are vulnerable to these issues.
 
No reader comments posted Reader Comments: 0 Contact Rich Kavanagh, the author of this article View a printer friendly version of this article Email this article to a friend RSS Feeds

Your Verification Number:


Please enter your Verification Number: