BugTraq
iTunes 12.0.1 for Windows: still COMPLETELY outdated and VULNERABLE 3rd party libraries Oct 24 2014 06:35PM
Stefan Kanthak (stefan kanthak nexgo de)
Hi @ll,

the just released iTunes 12.0.1 for Windows still (cf.
<http://seclists.org/fulldisclosure/2014/Jul/30>) comes
with COMPLETELY outdated and VULNERAEBLE 3rd party libraries
(as part of AppleMobileDeviceSupport.msi):

* libeay32.dll and ssleay32.dll 0.9.8d

are more than SEVEN years old and have at least 27 unfixed CVEs!

* libcurl.dll 7.16.2

is more than SEVEN years old and has at least 18 unfixed CVEs!
the current version is 7.38.0;
see <http://curl.haxx.se/docs/security.html>
for the fixed vulnerabilities!

Until Apple's developers, their QA and their managers start to
develop a sense for safety and security:
stay away from their (Windows) software!

regards
Stefan Kanthak

Timeline:
~~~~~~~~~

2014-06-06 informed vendor

2014-06-06 vendor sent automated response

... no more reaction

2014-07-03 requested status

... no answer

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus