Apple plugs security hole in iTunes. iTunes 4.8 update available.
Donna writes "Apple Computer has patched a flaw in iTunes that could open the door to a remote attack on a person's computer.
The fix was released as part of the company's iTunes 4.8 update. Earlier versions of the music software have a vulnerability within MPEG-4 file parsing, Apple said in a security advisory. A person who accesses a malicious MPEG-4 file could trigger a buffer overflow exploit, which could then allow an attacker to gain remote control of their computer without their knowledge or crash iTunes.
This is considered highly critical because it doesn't require significant user interaction, said Thomas Kristensen, chief technology officer at Secunia, which released an advisory on the security hole on Tuesday. If you visit a malicious Web site and have an MPEG-4 data stream handled by an iTunes application, you could be affected.
The iTunes update is designed to improve the validation checks that are used when MPEG-4 files are loaded. It is available for Mac OS X, Microsoft Windows XP and Microsoft Windows 2000.