HOME     MENU     SEARCH     NEWSLETTER    
THE ENTERPRISE SECURITY SUPERSITE. UPDATED ABOUT A MINUTE AGO.
You are here: Home / Cybercrime / iTunes Update Plugs 163 Security Holes
Build Apps 5x Faster
For Half the Cost Enterprise Cloud Computing
On Force.com
Apple Plugs 163 iTunes Security Holes
Apple Plugs 163 iTunes Security Holes
By Jennifer LeClaire / Enterprise Security Today Like this on Facebook Tweet this Link thison Linkedin Link this on Google Plus
PUBLISHED:
SEPTEMBER
14
2012
There are plenty of security threats making headlines this week, from a new version of the Blackhole exploit kit being released to a Pinterest hack that feeds spam to Twitter and Facebook to rumors around Anonymous and beyond.

But with the launch of the Apple iPhone 5 making headlines, and the iTunes updates being announced right alongside it, security researchers stood at attention when Apple released a security update for iTunes 10.7 that fixes a jaw dropping 163 vulnerabilities. The issue affects Windows 7, Vista, XP SP 2 or later.

"Visiting a maliciously crafted Web site may lead to an unexpected application termination or arbitrary code execution," Apple said in its security bulletin. "Multiple memory corruption issues existed in WebKit. These issues are addressed through improved memory handling."

No Big Threat?

We caught up with Wolfgang Kandek, CTO of Qualys, to get his take on the whopping number of vulnerabilities and what kind of target that puts on iTunes' users backs.

Kandek told us he doesn't think iTunes is very high on the priority list of the attackers -- and it is quite possible that none of the fixed vulnerabilities can actually be exploited through iTunes.

"We do not treat iTunes vulnerabilities different from other software packages," Kandek said. "Personally, I recommend customers to first address the most exploited attack vectors, such as outdated PDF readers, old Java installations, etc."

Beware Blackhole 2

The greater threat may be the new version of the Blackhole exploit kit Sophos is reporting. Sophos characterizes Blackhole as arguably the most successful exploit it has seen over the past couple of years.

According to Sophos, the new Blackhole exploit kit claims to: prevent direct download of executable payloads; only load exploit contents when the client is considered vulnerable; drop use of the PluginDetect library; remove some old exploits; and change from a predictable URL structure.

"The announcement also talks about improvements made to the admin interface," Fraser Howard, a security analyst at Sophos, wrote in a blog post. "This is important. The author's business is marketing this exploit kit against others on the market."

World Cup Phishers

In other security news, Symantec reports phishers have already taken the opportunity to start promoting the FIFA World Cup scheduled for Brazil in June 2014. Symantec said the World Cup is a favorite attack vehicle for phishers. In September 2012, phishing sites spoofed a popular Brazilian credit and debit card company using the 2014 FIFA World Cup as bait.

"The phishing sites were in Brazilian Portuguese. A number of the phishing sites featured Brazilian footballer Neymar da Silva. Phishers utilized a recently registered domain, hosted on servers based in Brazil, to create the phishing site," Symantec's Ashish Diwakar said in a blog post.

"A message given on the phishing page stated that the company offered $20,000 in prizes and a new car. It also offered zero billing charges on the customer's card for exclusive trips taken to the 2014 FIFA World Cup in Brazil. Customers were prompted to register for the offer by entering their personal data and credit card details."

Tell Us What You Think
Comment:

Name:

Demetri Alekseev:
Posted: 2012-09-16 @ 7:35am PT
Most are in WebKit, not iTunes. Poor title.

Like Us on FacebookFollow Us on Twitter
TOP STORIES NOW
MAY INTEREST YOU
High Quality CRM Data: Prevent, detect and fix errors at the point of data entry for Dynamics CRM. Trillium Software helps you achieve an accurate, synchronized, single view of customers. It's time to trust your data. Take a product tour and read CRM Analyst opinions here.
MORE IN CYBERCRIME
Product Information and Resources for Technology You Can Use To Boost Your Business
© Copyright 2014 NewsFactor Network, Inc. All rights reserved. Member of Accuserve Ad Network.