iTunes 10.5 released to fix 79 vulnerabilties on Windows, OS X to follow

Filed Under: Apple, Featured, iOS, Vulnerability

iTunes 10.5Apple released a mammoth update to iTunes for Windows today bumping the version number to 10.5. The update fixes 79 vulnerabilities in iTunes, although not for Mac OS X users.

The largest number of fixes, 73, affect WebKit and could cause remote code execution. WebKit is used to render HTML content from the iTunes store.

Fortunately these vulnerabilities can only be exploited through a man-in-the-middle attack while using iTunes.

Other fixes resolve remote code execution flaws in CoreFoundation, ColorSync, CoreAudio, CoreMedia and ImageIO.

According to SANS Internet Storm Center, Apple will be releasing fixes for OS X users as part of the yet unreleased updates for 10.6 (Snow Leopard) and 10.7 (Lion). Users of OS X 10.5 and earlier will be left unprotected.

iCloud logoiTunes 10.5 for OS X is available as well, but only includes new features, not security fixes. iTunes 10.5 introduces iCloud support, wireless syncing and support for iOS 5.

One piece of good news is that iTunes no longer requires QuickTime on Windows machines. If you don't need/want QuickTime this might be a great opportunity to remove it, reducing the number of applications you need to keep patched.

I hope we see an update for Mac OS X soon as Apple still have not fixed the six week old directory services vulnerability and the three week old password change vulnerability.

If you are a Mac user interested in protecting your computer consider downloading our Sophos Anti-Virus for Mac Home Edition for free protection from viruses, Trojans and other malware.

, , , , , ,

You might like

5 Responses to iTunes 10.5 released to fix 79 vulnerabilties on Windows, OS X to follow

  1. How about Quicktime users? Still no patch for Quicktime (or it's not affected).

    I use Quicktime and NOT itunes and I'm annoyed for constantly having itunes pushed to my face (listed as one of the software I need to "update/install" in Apple Software update).

  2. Sean · 1046 days ago

    looks like they've pulled this link already - and have a "10.5 coming soon" message on their website..

  3. mhea09 · 1045 days ago

    so that's only for itunes users..but thanks for the inforamation anyhow.

  4. mroyakkers · 1043 days ago

    i Tunes 10.5 is problems with XP, it uses 100 % CPU when started, i cant find the problem, installing it again dos not help!!

  5. dcjim2 · 1038 days ago

    I am having MULTIPLE problems with 10.5
    1) won't load iTunes store
    2) try to sync my iPhone and update to iOS5 and it freezes
    3) CPU usage jumps to 100% and freezes everything else
    4) won't shut down - have to bring up Task Manager to shut the program down

    Anyone got any ideas for fixes? Tried un- and re-installing with no change.

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s

About the author

Chester Wisniewski is a Senior Security Advisor at Sophos Canada. He provides advice and insight into the latest threats for security and IT professionals with the goal of providing clear guidance on complex topics. You can follow Chester on Twitter as @chetwisniewski, on App.net as Chester, Chester Wisniewski on Google Plus or send him an email at chesterw@sophos.com.