Apple Itunes CoreAudio Buffer Overflow Remote Code Execution

Posted: October 13, 2011 in Vulnerabilities

A remote code execution vulnerability is present in CoreAudio component of Apple ITunes. The flaw is caused by a buffer overflow existed in the handling of audio stream encoded with the advanced audio code. Successful exploitation could allow an attacker to execute remote code. The exploit requires the user to visit the ITunes Store using ITunes.

October 12, 2011


