[prev in list] [next in list] [prev in thread] [next in thread] 

List:       full-disclosure
Subject:    [FD] iTunes 12.0.1 for Windows: still COMPLETELY outdated and VULNERABLE 3rd party libraries
From:       "Stefan Kanthak" <stefan.kanthak () nexgo ! de>
Date:       2014-10-24 18:35:34
Message-ID: DB881C69AFE44885B7E724127E22C1A2 () celsius
[Download RAW message or body]

Hi @ll,

the just released iTunes 12.0.1 for Windows still (cf.
<http://seclists.org/fulldisclosure/2014/Jul/30>) comes
with  COMPLETELY outdated and VULNERAEBLE 3rd party libraries
(as part of AppleMobileDeviceSupport.msi):


* libeay32.dll and ssleay32.dll 0.9.8d

  are more than SEVEN years old and have at least 27 unfixed CVEs!


* libcurl.dll 7.16.2

  is more than SEVEN years old and has at least 18 unfixed CVEs!
  the current version is 7.38.0;
  see <http://curl.haxx.se/docs/security.html>
  for the fixed vulnerabilities!


Until Apple's developers, their QA and their managers start to
develop a sense for safety and security:
stay away from their (Windows) software!


regards
Stefan Kanthak


Timeline:
~~~~~~~~~

2014-06-06    informed vendor

2014-06-06    vendor sent automated response

... no more reaction

2014-07-03    requested status

... no answer

_______________________________________________
Sent through the Full Disclosure mailing list
http://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: http://seclists.org/fulldisclosure/
[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic