Get PGbiz on your
Pocket Gamer Biz      LOG IN Register
 
USEFUL STUFF
RSS FEED
SEND US NEWS
CONTACT US
ABOUT US
ADVERTISE
EVENTS
PARTNERS
Play free Bingo games on Moon Bingo. Grab the best free bingo bonuses at Gossip Bingo UK!
Pocket Gamer on NewsNow
dx.net
 PG.BIZ NEWS
iTunes 8 security issue rated 'High' by National Vulnerability Database
iPhone users besieged by Trojan software
 Product: iPhone news 
 Manufacturer: Apple 
by Spanner Spencer
A vulnerability within QuickTime 7.5.5 and iTunes 8.0 has been uncovered by security researchers, and given a CVSS Severity rating of 9.3 (high) by the National Vulnerability Database.

The flaw in security is being exploited by malicious code hidden inside embedded MP3 files on web pages and through a long type attribute in a QuickTime tag. According to the VND, the security gap is a "Heap-based buffer overflow in Apple QuickTime 7.5.5 and iTunes 8.0 [that] allows remote attackers to cause a denial of service (browser crash) or possibly execute arbitrary code."

So far there's been no response from Apple regarding the bug, though only last week it addressed other bugs in the QuickTime system.

People are also being warned against an email that offers 'Virtual iPhone games!" and sometimes contains the subject line "Apple: The most popular game!". The email attachment (Penguin.Panic.zip) has been confirmed to contain the malware listed as Agent-HNY Trojan, so caution is advised when it comes to Apple related messages and websites for the time being.
Join the discussion
Be the first to comment
Digg, bookmark, or subscribe

Reviewer photo
Spanner Spencer 19/9/2008
 RELATED STORIES
MP_see2010_banner