Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Apple iTunes before 10.5.1 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Apple iTunes Update 代码注入漏洞
Vulnerability Description
iTunes是一款免费应用程序,iPod和iPhone的媒体文件管理。 Apple iTunes 没有正确的校验更新的真实性,导致恶意代码注入漏洞。通过中间人攻击方式,可以利用此漏洞在升级中使用包含木马的更新,执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A