Apple Uses Security Advisory to Push iTunes 10 Upgrade
Social networking features, a rockin' new logo and GUI improvements aren't the only reason you should upgrade to iTunes 10, says Apple. The update to Apple's popular music player software, released on Wednesday, also fixes a bunch of gaping vulnerabilities that could make earlier versions susceptible to Web based attacks.
On Wednesday, CEO Steve Jobs took the stage to introduce a raft of new products, including a new version of iTunes. The update includes new social networking capabilities of iTunes, which Apple has dubbed "Ping," and which allow users to share data on what music they're listening to. (Stereolab, if you were wondering.)
Editor's Pick
Behind the scenes, though, Apple quietly issued a security advisory suggesting another good reason to upgrade to the new player: a fix for some 13 known vulnerabilities in Webkit for Windows, a component of Apple's Safari Web browser and also of iTunes for Windows.
According to Apple, iTunes 10 incorporates security fixes provided in the Safari 5.0 release, including fixes for across site scripting, information leakage and memory corruption vulnerabilities. The holes, including a flaw in the way Safari handled form AutoFill functions, could make users of iTunes for WIndows 7, Windows Vista and Windows XP SP2 systems vulnerable to remote exploits using maliciously crafted Web sites or RSS feeds.
As reported by Threatpost researchers at the annual Black Hat Briefings in Las Vegas showed how the AutoFill vulnerability could enable attackers to siphon personal information about users from Safari browsers.
Apple posted details of the patched vulnerabilities on its support Web site.
Commenting on this Article is closed.
Today's Most Popular
- Attackers Using Fake Google Analytics Code to Redirect Users to Black Hole Exploit Kit
- Google Releases Beta of Chrome for Android
- Flash With Sandbox in the Works for Firefox
- DDoS Attacks Take on Political Motivations as Attackers Evolve
- Anonymous Leaks FBI, Scotland Yard Phone Call Detailing Hacking Investigations
Most Commented Stories
-
Mac OS X Sandbox Security Hole Uncovered (5)
-
Anonymous Leaks FBI, Scotland Yard Phone Call Detailing Hacking Investigations (5)
-
Privacy Fail: Is Uncle Sam Encouraging Bad Security? (8)
-
Flash With Sandbox in the Works for Firefox (4)
-
Attackers Using Fake Google Analytics Code to Redirect Users to Black Hole Exploit Kit (3)
Newsletter Sign-up
Take Our Poll
Listen to Latest Podcasts
-
-
You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.
-
You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.




