Alert Number: 092309-01
Alert Date: 09/23/09
Alert Title: Patch available for iTunes vulnerability
Update-to: None.
OS/Platform/Application:
Apple iTunes (on Windows and Mac systems)
Category: ALERT
Severity: HIGH
Attention: iTunes users, System Administrators, Desktop Support Personnel.
Summary: Apple has released an updated version of its popular iTunes software. iTunes 9.0.1 includes a fix for a vulnerability in way iTunes handles .pls files. Files ending in ".pls" are playlists that store information about songs such as titles and lengths. Successful exploitation of this vulnerability could result in system crash or complete takeover of a vulnerable computer.
Recommended Actions: iTunes users are encouraged to update to version 9.0.1 as soon as possible.
Readers are encouraged to share this alert with family, friends, and associates.
ITS Actions: N/A
Resources:
iTunes 9.0.1 security content page:
http://support.apple.com/kb/HT3884
iTunes download page:
http://www.apple.com/itunes/download/