CVE-2008-3434

Description

Apple iTunes before 10.5.1 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.

Risk Information

Base Score
8.1
MODERATE
Vector
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.698

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in Apple iTunes For Mac 4.7Mac
Multiple Vulnerabilities are affected in Apple iTunes For Mac 4.6Mac
Multiple Vulnerabilities are affected in Apple iTunes For Mac 4.7.1Mac
Multiple Vulnerabilities are affected in Apple iTunes For Mac 6.0.1Mac
Multiple Vulnerabilities are affected in Apple iTunes For Mac 6.0.2Mac
Multiple Vulnerabilities are affected in Apple iTunes For Mac 1.0Mac
Vulnerabilities CVE-2008-3434,CVE-2009-0950,CVE-2010-1777 are affected in Apple iTunes For Mac 1.1Mac
Multiple Vulnerabilities are affected in Apple iTunes For Mac 1.1.1Mac
Multiple Vulnerabilities are affected in Apple iTunes For Mac 1.1.2Mac
Vulnerabilities CVE-2008-3434,CVE-2009-0950,CVE-2009-2817,CVE-2010-1777 are affected in Apple iTunes For Mac 2.0Mac
Multiple Vulnerabilities are affected in Apple iTunes For Mac 2.0.1Mac
Multiple Vulnerabilities are affected in Apple iTunes For Mac 2.0.2Mac
Multiple Vulnerabilities are affected in Apple iTunes For Mac 2.0.3Mac
Multiple Vulnerabilities are affected in Apple iTunes For Mac 2.0.4Mac
Vulnerabilities CVE-2008-3434,CVE-2009-0950,CVE-2009-2817,CVE-2010-1777 are affected in Apple iTunes For Mac 3.0Mac
Multiple Vulnerabilities are affected in Apple iTunes For Mac 3.0.1Mac
Vulnerabilities CVE-2008-3434,CVE-2009-0950,CVE-2009-2817 are affected in Apple iTunes For Mac 4.0Mac
Multiple Vulnerabilities are affected in Apple iTunes For Mac 4.0.1Mac
Vulnerabilities CVE-2008-3434,CVE-2009-0950,CVE-2009-2817 are affected in Apple iTunes For Mac 4.1Mac
Vulnerabilities CVE-2008-3434,CVE-2009-0950,CVE-2009-2817 are affected in Apple iTunes For Mac 4.2Mac
Multiple Vulnerabilities are affected in Apple iTunes For Mac 4.5Mac
Vulnerabilities CVE-2008-3434,CVE-2009-0950,CVE-2009-2817 are affected in Apple iTunes For Mac 4.8Mac
Vulnerabilities CVE-2008-3434,CVE-2009-0950,CVE-2009-2817 are affected in Apple iTunes For Mac 4.9Mac
Multiple Vulnerabilities are affected in Apple iTunes For Mac 5.0Mac
Multiple Vulnerabilities are affected in Apple iTunes For Mac 5.0.1Mac
Vulnerabilities CVE-2008-3434,CVE-2009-0950,CVE-2009-2817 are affected in Apple iTunes For Mac 6.0Mac
Multiple Vulnerabilities are affected in Apple iTunes For Mac 6.0.3Mac
Multiple Vulnerabilities are affected in Apple iTunes For Mac 6.0.4Mac
Multiple Vulnerabilities are affected in Apple iTunes For Mac 6.0.4.2Mac
Vulnerabilities CVE-2008-3434 are affected in Apple iTunes For Mac 6.0.5--Mac
Vulnerabilities CVE-2008-3434,CVE-2008-3634,CVE-2009-0950,CVE-2010-1777 are affected in Apple iTunes For Mac 1.0Mac
Vulnerabilities CVE-2008-3434,CVE-2008-3634,CVE-2009-0950,CVE-2010-1777 are affected in Apple iTunes For Mac 1.1Mac
Vulnerabilities CVE-2008-3434,CVE-2008-3634,CVE-2009-0950,CVE-2010-1777 are affected in Apple iTunes For Mac 1.1.1Mac
Vulnerabilities CVE-2008-3434,CVE-2008-3634,CVE-2009-0950,CVE-2010-1777 are affected in Apple iTunes For Mac 1.1.2Mac
Vulnerabilities CVE-2008-3434,CVE-2008-3634,CVE-2009-0950,CVE-2010-1777 are affected in Apple iTunes For Mac 2.0Mac
Vulnerabilities CVE-2008-3434,CVE-2008-3634,CVE-2009-0950,CVE-2010-1777 are affected in Apple iTunes For Mac 2.0.1Mac
Vulnerabilities CVE-2008-3434,CVE-2008-3634,CVE-2009-0950,CVE-2010-1777 are affected in Apple iTunes For Mac 2.0.2Mac
Vulnerabilities CVE-2008-3434,CVE-2008-3634,CVE-2009-0950,CVE-2010-1777 are affected in Apple iTunes For Mac 2.0.3Mac
Vulnerabilities CVE-2008-3434,CVE-2008-3634,CVE-2009-0950,CVE-2010-1777 are affected in Apple iTunes For Mac 2.0.4Mac
Vulnerabilities CVE-2008-3434,CVE-2008-3634,CVE-2009-0950,CVE-2010-1777 are affected in Apple iTunes For Mac 3.0Mac
Vulnerabilities CVE-2008-3434,CVE-2008-3634,CVE-2009-0950,CVE-2010-1777 are affected in Apple iTunes For Mac 3.0.1Mac
Vulnerabilities CVE-2008-3434,CVE-2008-3634,CVE-2009-0950 are affected in Apple iTunes For Mac 4.0Mac
Vulnerabilities CVE-2008-3434,CVE-2008-3634,CVE-2009-0950 are affected in Apple iTunes For Mac 4.1Mac
Vulnerabilities CVE-2008-3434,CVE-2008-3634,CVE-2009-0950 are affected in Apple iTunes For Mac 4.2Mac
Vulnerabilities CVE-2008-3434,CVE-2008-3634,CVE-2009-0950 are affected in Apple iTunes For Mac 4.8Mac
Vulnerabilities CVE-2008-3434,CVE-2008-3634,CVE-2009-0950 are affected in Apple iTunes For Mac 4.9Mac
Vulnerabilities CVE-2008-3434,CVE-2008-3634,CVE-2009-0950 are affected in Apple iTunes For Mac 6.0Mac

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234