—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA1
APPLE-SA-2014-05-15-2 iTunes 11.2
iTunes 11.2 is now available and addresses the following:
iTunes
Available for: Windows 8, Windows 7, Vista, XP SP3 or later
Impact: An attacker in a privileged network position can obtain
iTunes credentials
Description: Set-Cookie HTTP headers would be processed even if the
connection closed before the header line was complete. An attacker
could strip security settings from the cookie by forcing the
connection to close before the security settings were sent, and then
obtain the value of the unprotected cookie. This issue was addressed
by ignoring incomplete HTTP header lines.
CVE-ID
CVE-2014-1296
iTunes 11.2 may be obtained from:
http://www.apple.com/itunes/download/
For Windows XP / Vista / Windows 7 / Windows 8:
The download file is named: “iTunesSetup.exe”
Its SHA-1 digest is: 0e96aec6ba9959fd288e662b4fcbe58fd2bb89eb
For 64-bit Windows XP / Vista / Windows 7 / Windows 8:
The download file is named: “iTunes64Setup.exe”
Its SHA-1 digest is: eb7da1d648c41a5b1e3ccc00ca26dcaa1f6d04d5
Information will also be posted to the Apple Security Updates
web site: http://support.apple.com/kb/HT1222
This message is signed with Apple’s Product Security PGP key,
and details are available at:
https://www.apple.com/support/security/pgp/
—–BEGIN PGP SIGNATURE—–
Version: GnuPG/MacGPG2 v2.0.22 (Darwin)
Comment: GPGTools – http://gpgtools.org
iQIcBAEBAgAGBQJTdSj9AAoJEBcWfLTuOo7tmnoP/i5B4nL/Al9kdEQHN+EhaVl5
i406n6dVtfo/MdBz2jB99wkAsEQp2xNqBs2Bw1nEB9InPo4w/Jy6LkPR5VR9E+c/
HAn9TnN0yUGu6KNfm02G+8qWoMfCL+aHhL8uEN8/0ljjv2Wirf4SykmoLTxcpC7x
6Z4ABeNhQfRpIZVHsmLSNZ1WrpChs74ycPkM9dgI5jNe6gC3W3sFrPK63I8fwiIU
I1Qfb89C6u7b0Csmd1jhAss+0fXkiR6k7VsZEsIeS1yJtIV1mFFULPAOd2MYcLTU
64u6dHWgMHcjLkIDKqzWjyCjlFZ6/H5hMnxVLuNnh/pKbcSUd/naSAsRldc6vXE6
S/wyjAPisyWZ5bsi6KZSJmaAScBMoMQXak1HcaCJEwKqREiyUoBGI6m2Z21IN8AX
L1ymTwFWY/K4VyrsR+CpBtxukLIKQWUwQADCfSGEgTSF4wYeRQVjknAtMJXuqZi2
8AGamj3Cl2tWHvi3rWRjoQSKb2ZTuFmkWkXf5OUa7UWa6qEnV9pZdAdqomVXNRsR
vGllQT+iQvAccHyXR5+jiCatSzd6N70iXejYo4jFsMlksYe5gltbYPu3bPFgqXmP
t2+fISgNB4mNx11iy2qwqbQC2NVeguqjD5V/u1wXSJ/Pl774xHrmL9F4evwY7Fla
+RyBNGTKqHzsoL+ucr3i
=ehLN
—–END PGP SIGNATURE—–
—–BEGIN PGP SIGNATURE—–
Comment: GPGTools – http://gpgtools.org
iQIcBAEBAgAGBQJTdSybAAoJEBcWfLTuOo7t0O4QAJ0ZfBWThtPuyXNA4peF7O7r
xQRz+Ulew7QoiZ9nwtHQontm8J7htStmfgEFC3+tnpNGMdQuSuuegLbHoxza56Tf
GQb3jtjM5s1WoJAhCAZaQR90152qHHd46On2dVXO3a9+Gc1CyMjYvrO1eJkscjF2
0g/Nw67TJGzt+T+JBg5eokP8Abd+tFgHQzptXIEhRVe08MWZonOMhqixqKSeM476
72ie66QR2PXv/pF8XlOOMDYw5wn+iIy8s05ZTXZNA4FwidxOcw5uBDqrhUyHup0x
Dfv1mEREevsDq4pFVXQghKpzMRaROfFtmpn/c1KQbYvhEtDzZqXiEZ0JV3Vq2+ny
qF9ooD/sotjeqULwWmnjSB3F9smUtf74OGHHlUUUzQqzFFxWNFej9gMs62uQsBv6
dG5wEt7Ugo0I12Et0l8rfdGgmrUuHd+8qnsf8XDCFIzzVkDEkM9qyyAjobvD7DgD
q3piL9ioG1Gp2ug+vx60gZh2PXw/Acq0sdhr4Gj03pIgOsRy8wYM1ZcxdP6N1Hmu
+Enqz8J1LY3fDMn/uN8/IDWHCV6SNAzGBEaRVtWkSmZ4rY8Mhls9whmcT/zOHf11
nmuMTl/C/VotTnucvbEA/fas2N5IoOsltNg8iM8WI3bUQ1DsSkcYLKziuYkqKcIq
uDY6k9wl2hoi/o59O+Y4
=u5qr
—–END PGP SIGNATURE—–
_______________________________________________
Do not post admin requests to the list. They will be ignored.
Security-announce mailing list (Security-announce@lists.apple.com)