Executive Summary

Informations
Name CVE-2009-0950 First vendor Publication 2009-06-02
Vendor Cve Last vendor Modification 2018-10-10

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:M/Au:N/C:C/I:C/A:C)
Cvss Base Score 9.3 Attack Range Network
Cvss Impact Score 10 Attack Complexity Medium
Cvss Expoit Score 8.6 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

Stack-based buffer overflow in Apple iTunes before 8.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an itms: URL with a long URL component after a colon.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0950

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-119 Failure to Constrain Operations within the Bounds of a Memory Buffer

OVAL Definitions

Definition Id: oval:org.mitre.oval:def:17099
 
Oval ID: oval:org.mitre.oval:def:17099
Title: Stack-based buffer overflow in Apple iTunes before 8.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an itms: URL with a long URL component after a colon
Description: Stack-based buffer overflow in Apple iTunes before 8.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an itms: URL with a long URL component after a colon.
Family: windows Class: vulnerability
Reference(s): CVE-2009-0950
Version: 6
Platform(s): Microsoft Windows 2000
Microsoft Windows 7
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Vista
Microsoft Windows XP
Microsoft Windows 8
Microsoft Windows Server 2012
Product(s): Apple iTunes
Definition Synopsis:

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 231

SAINT Exploits

Description Link
Apple iTunes itms: URL buffer overflow More info here

ExploitDB Exploits

id Description
2010-01-14 Apple iTunes 8.1.x (daap) Buffer overflow remote exploit (CVE-2009-0950)
2009-06-12 Apple iTunes 8.1.1.10 (itms/itcp) Remote Buffer Overflow Exploit (win)
2009-06-03 Apple iTunes 8.1.1 (ITMS) Multiple Protocol Handler BOF Exploit (meta)

OpenVAS Exploits

Date Description
2009-06-04 Name : Apple iTunes 'itms:' URI Stack Buffer Overflow Vulnerability
File : nvt/gb_apple_itunes_bof_vuln_jun09.nasl

Open Source Vulnerability Database (OSVDB)

Id Description
54833 Apple iTunes itms: URI Handling Overflow

A buffer overflow exists in iTunes. The application fails to validate itms:// URI data resulting in a stack overflow. With a specially crafted link, a context-dependent attacker can cause arbitrary code execution resulting in a loss of integrity.

Snort® IPS/IDS

Date Description
2014-01-10 Apple iTunes protocol handler stack buffer overflow attempt
RuleID : 20167 - Revision : 2 - Type : WEB-CLIENT
2014-01-10 Apple iTunes protocol handler stack buffer overflow attempt
RuleID : 20166 - Revision : 2 - Type : WEB-CLIENT
2014-01-10 Apple iTunes protocol handler stack buffer overflow attempt
RuleID : 20165 - Revision : 2 - Type : WEB-CLIENT
2014-01-10 Apple iTunes protocol handler stack buffer overflow attempt
RuleID : 20164 - Revision : 2 - Type : WEB-CLIENT
2014-01-10 Apple iTunes protocol handler stack buffer overflow attempt
RuleID : 20163 - Revision : 2 - Type : WEB-CLIENT
2014-01-10 Apple iTunes ITPC protocol handler stack buffer overflow attempt
RuleID : 15707 - Revision : 9 - Type : FILE-MULTIMEDIA
2014-01-10 Apple iTunes DAAP protocol handler stack buffer overflow attempt
RuleID : 15706 - Revision : 6 - Type : FILE-MULTIMEDIA
2014-01-10 Apple iTunes PCAST protocol handler stack buffer overflow attempt
RuleID : 15705 - Revision : 5 - Type : FILE-MULTIMEDIA
2014-01-10 Apple iTunes ITMSS protocol handler stack buffer overflow attempt
RuleID : 15704 - Revision : 6 - Type : FILE-MULTIMEDIA
2014-01-10 Apple iTunes ITMS protocol handler stack buffer overflow attempt
RuleID : 15703 - Revision : 6 - Type : FILE-MULTIMEDIA

Nessus® Vulnerability Scanner

Date Description
2009-06-02 Name : The remote Windows host contains an application that is affected by a buffer ...
File : itunes_8_2.nasl - Type : ACT_GATHER_INFO
2009-06-02 Name : The remote host contains an application that is affected by a buffer overflow...
File : itunes_8_2_banner.nasl - Type : ACT_GATHER_INFO
2009-06-02 Name : The remote Mac OS X host contains an application that is affected by a buffer...
File : macosx_itunes_8_2.nasl - Type : ACT_GATHER_INFO

Sources (Detail)

Source Url
APPLE http://lists.apple.com/archives/security-announce/2009/Jun/msg00001.html
BID http://www.securityfocus.com/bid/35157
BUGTRAQ http://www.securityfocus.com/archive/1/504043/100/0/threaded
CONFIRM http://support.apple.com/kb/HT3592
EXPLOIT-DB https://www.exploit-db.com/exploits/8861
https://www.exploit-db.com/exploits/8934
MISC http://redpig.dataspill.org/2009/05/drive-by-attack-for-itunes-811.html
http://static.dataspill.org/releases/itunes/itms_overflow.rb
OSVDB http://osvdb.org/54833
OVAL https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.ova...
SECTRACK http://www.securitytracker.com/id?1022313
SECUNIA http://secunia.com/advisories/35314
VUPEN http://www.vupen.com/english/advisories/2009/1470
XF https://exchange.xforce.ibmcloud.com/vulnerabilities/50899

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
9
10
11
12
13
14
Date Informations
2021-05-04 12:09:17
  • Multiple Updates
2021-04-22 01:09:37
  • Multiple Updates
2020-05-23 13:16:52
  • Multiple Updates
2020-05-23 01:40:10
  • Multiple Updates
2020-05-23 00:23:30
  • Multiple Updates
2018-10-11 00:19:32
  • Multiple Updates
2017-11-29 12:02:58
  • Multiple Updates
2017-09-29 09:24:07
  • Multiple Updates
2017-08-17 09:22:30
  • Multiple Updates
2016-06-28 17:37:12
  • Multiple Updates
2016-04-26 18:42:12
  • Multiple Updates
2014-02-17 10:49:17
  • Multiple Updates
2014-01-19 21:25:46
  • Multiple Updates
2013-11-04 21:20:40
  • Multiple Updates
2013-05-10 23:46:49
  • Multiple Updates