CVE-2005-0043
50Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 69%
from disclosure to weapon0 days
Published on NVDJan 19
1st PoCJan 16
metasploitJan 11
exploitation probability
69%top 1% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
Buffer overflow in Apple iTunes 4.7 allows remote attackers to execute arbitrary code via a long URL in (1) .m3u or (2) .pls playlist files.
Affected products
n/a · n/apublic PoCs found — 2
exploitdbwww.exploit-db.com/exploits/758unverifiedexploitdbwww.exploit-db.com/exploits/16562unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://lists.apple.com/archives/security-announce/2005/Jan/msg00000.htmlhttp://secunia.com/advisories/13804http://securitytracker.com/id?1012839https://exchange.xforce.ibmcloud.com/vulnerabilities/18851http://www.idefense.com/application/poi/display?id=180&type=vulnerabilitieshttp://www.kb.cert.org/vuls/id/377368http://www.osvdb.org/12833http://www.securityfocus.com/bid/12238