HTTP: Illegal iTunes Playlist URL

This signature detects attempts to exploit a known vulnerability in iTunes parsing handler. iTunes 4.7 is vulnerable. Attackers can submit iTunes play lists that refer to illegal URLs, which can create a denial-of-service condition or allow them to execute arbitrary code.

Extended Description

Apple iTunes is prone to a buffer overflow vulnerability. This issue is exposed when the application parses 'm3u' and 'pls' playlist files. As these files may originate from an external source, this issue is considered remotely exploitable. If the vulnerability is successfully exploited, it will result in execution of arbitrary code in the context of the user running the application.

Affected Products

Apple itunes

Short Name
HTTP:STC:ITUNES-PL
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2005-0043 Illegal Playlist URL bid:12238 iTunes
Release Date
02/11/2005
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3375
False Positive
Unknown
Vendors

Apple

CVSS Score

7.5

Found a potential security threat?