Apples current iTunes 11.2.2 for Windows comes with the following
COMPLETELY outdated and vulnerable 3rd party libraries (as part of
AppleApplicationSupport.msi):
* libeay32.dll and ssleay32.dll 0.9.8d
are more than SEVEN years old and have at least 27 unfixed CVEs!
the current version is 0.9.8za, see <http://www.openssl.org/news/>
* libcurl.dll 7.16.2
is more than SEVEN years old and has at least 18 unfixed CVEs!
the current version is 7.37.0;
see <http://curl.haxx.se/docs/ security.html>
for the fixed vulnerabilities!
* libxml2.dll 2.6.0.0
is more than TEN years old and has at least 17 unfixed CVEs!
the current version is 2.9.1, for the latest vulnerability see
CVE-2013-0339
* icuuc40.dll, icuin40.dll, icudt49.dll, libicuuc.dll and libicuin.dll 49.1.1
have at least 4 unfixed CVEs: CVE-2013-2419, CVE-2013-2383, CVE-2013-2384,
CVE-2013-1569
Until Apples developers start to develop a sense for safety and security:
stay away from their (Windows) software!
regards
Stefan Kanthak
stefan.kanthak@nexgo.de
Timeline:
~~~~~~~~~
2014-06-06 informed vendor
2014-06-06 vendor sent automated response
... no more reaction
2014-07-03 requested status
... no answer
2014-07-07 report published
//The information contained within this publication is
//supplied "as-is"with no warranties or guarantees of fitness
//of use or otherwise. Bot24, Inc nor Bradley Sean Susser accepts
//responsibility for any damage caused by the use or misuse of
//this information
COMPLETELY outdated and vulnerable 3rd party libraries (as part of
AppleApplicationSupport.msi):
* libeay32.dll and ssleay32.dll 0.9.8d
are more than SEVEN years old and have at least 27 unfixed CVEs!
the current version is 0.9.8za, see <http://www.openssl.org/news/>
* libcurl.dll 7.16.2
is more than SEVEN years old and has at least 18 unfixed CVEs!
the current version is 7.37.0;
see <http://curl.haxx.se/docs/
for the fixed vulnerabilities!
* libxml2.dll 2.6.0.0
is more than TEN years old and has at least 17 unfixed CVEs!
the current version is 2.9.1, for the latest vulnerability see
CVE-2013-0339
* icuuc40.dll, icuin40.dll, icudt49.dll, libicuuc.dll and libicuin.dll 49.1.1
have at least 4 unfixed CVEs: CVE-2013-2419, CVE-2013-2383, CVE-2013-2384,
CVE-2013-1569
Until Apples developers start to develop a sense for safety and security:
stay away from their (Windows) software!
regards
Stefan Kanthak
stefan.kanthak@nexgo.de
Timeline:
~~~~~~~~~
2014-06-06 informed vendor
2014-06-06 vendor sent automated response
... no more reaction
2014-07-03 requested status
... no answer
2014-07-07 report published
//The information contained within this publication is
//supplied "as-is"with no warranties or guarantees of fitness
//of use or otherwise. Bot24, Inc nor Bradley Sean Susser accepts
//responsibility for any damage caused by the use or misuse of
//this information