← Back

CVE-2008-3434

nvd nist
Published: Aug 1, 2008Modified: Apr 23, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

Apple iTunes before 10.5.1 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.

Affected (30)

Products: Apple: Itunes
1 product
Itunes
Configuration A
30 vulnerable
Vulnerable SoftwareAffected Versions
Apple
Up to 6.0.5
Version 1.0
Version 1.1.1
Version 1.1.2
Version 1.1
Version 2.0.1
Version 2.0.2
Version 2.0.3
Version 2.0.4
Version 2.0
Version 3.0.1
Version 3.0
Version 4.0.1
Version 4.0
Version 4.1
Version 4.2
Version 4.5
Version 4.6
Version 4.7.1
Version 4.7
Version 4.8
Version 4.9
Version 5.0.1
Version 5.0
Version 6.0.1
Version 6.0.2
Version 6.0.3
Version 6.0.4.2
Version 6.0.4
Version 6.0

Timeline

No history available yet.