Release date:
Updated on:
Affected Systems:
Apple iTunes <11.2.1
Description:
--------------------------------------------------------------------------------
Bugtraq id: 67457
CVE (CAN) ID: CVE-2014-1347
ITunes is a digital media playback app. It is a free app for Mac and PC users to manage and play your digital music and videos.
During the restart process of Apple iTunes earlier than 11.2.1 on OS X, set/Users and/Users/Shared to global writable permissions, which allows local Users to operate through standard file systems, attackers can exploit this vulnerability to modify files and obtain arbitrary user accounts.
<* Source: Apple
Link: http://support.apple.com/kb/HT6251
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Apple
-----
For this reason, Apple has released a Security Bulletin (ht6133) and corresponding patches:
Ht6133: About the security content of iTunes 11.2.1
Link: http://support.apple.com/kb/HT6251
Patch download: http://support.apple.com/kb/TS5434
This article permanently updates the link address: