看板 Bugtraq 關於我們 聯絡資訊
--Apple-Mail=_3EB900CF-8B2A-4DCC-B7C7-3C0BC2BF7EEF Content-Transfer-Encoding: 7bit Content-Type: text/plain; charset=us-ascii -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 APPLE-SA-2014-05-15-2 iTunes 11.2 iTunes 11.2 is now available and addresses the following: iTunes Available for: Windows 8, Windows 7, Vista, XP SP3 or later Impact: An attacker in a privileged network position can obtain iTunes credentials Description: Set-Cookie HTTP headers would be processed even if the connection closed before the header line was complete. An attacker could strip security settings from the cookie by forcing the connection to close before the security settings were sent, and then obtain the value of the unprotected cookie. This issue was addressed by ignoring incomplete HTTP header lines. CVE-ID CVE-2014-1296 iTunes 11.2 may be obtained from: http://www.apple.com/itunes/download/ For Windows XP / Vista / Windows 7 / Windows 8: The download file is named: "iTunesSetup.exe" Its SHA-1 digest is: 0e96aec6ba9959fd288e662b4fcbe58fd2bb89eb For 64-bit Windows XP / Vista / Windows 7 / Windows 8: The download file is named: "iTunes64Setup.exe" Its SHA-1 digest is: eb7da1d648c41a5b1e3ccc00ca26dcaa1f6d04d5 Information will also be posted to the Apple Security Updates web site: http://support.apple.com/kb/HT1222 This message is signed with Apple's Product Security PGP key, and details are available at: https://www.apple.com/support/security/pgp/ -----BEGIN PGP SIGNATURE----- Version: GnuPG/MacGPG2 v2.0.22 (Darwin) Comment: GPGTools - http://gpgtools.org iQIcBAEBAgAGBQJTdSj9AAoJEBcWfLTuOo7tmnoP/i5B4nL/Al9kdEQHN+EhaVl5 i406n6dVtfo/MdBz2jB99wkAsEQp2xNqBs2Bw1nEB9InPo4w/Jy6LkPR5VR9E+c/ HAn9TnN0yUGu6KNfm02G+8qWoMfCL+aHhL8uEN8/0ljjv2Wirf4SykmoLTxcpC7x 6Z4ABeNhQfRpIZVHsmLSNZ1WrpChs74ycPkM9dgI5jNe6gC3W3sFrPK63I8fwiIU I1Qfb89C6u7b0Csmd1jhAss+0fXkiR6k7VsZEsIeS1yJtIV1mFFULPAOd2MYcLTU 64u6dHWgMHcjLkIDKqzWjyCjlFZ6/H5hMnxVLuNnh/pKbcSUd/naSAsRldc6vXE6 S/wyjAPisyWZ5bsi6KZSJmaAScBMoMQXak1HcaCJEwKqREiyUoBGI6m2Z21IN8AX L1ymTwFWY/K4VyrsR+CpBtxukLIKQWUwQADCfSGEgTSF4wYeRQVjknAtMJXuqZi2 8AGamj3Cl2tWHvi3rWRjoQSKb2ZTuFmkWkXf5OUa7UWa6qEnV9pZdAdqomVXNRsR vGllQT+iQvAccHyXR5+jiCatSzd6N70iXejYo4jFsMlksYe5gltbYPu3bPFgqXmP t2+fISgNB4mNx11iy2qwqbQC2NVeguqjD5V/u1wXSJ/Pl774xHrmL9F4evwY7Fla +RyBNGTKqHzsoL+ucr3i =ehLN -----END PGP SIGNATURE----- --Apple-Mail=_3EB900CF-8B2A-4DCC-B7C7-3C0BC2BF7EEF Content-Transfer-Encoding: 7bit Content-Disposition: attachment; filename=signature.asc Content-Type: application/pgp-signature; name=signature.asc Content-Description: Message signed with OpenPGP using GPGMail -----BEGIN PGP SIGNATURE----- Comment: GPGTools - http://gpgtools.org iQIcBAEBAgAGBQJTdSybAAoJEBcWfLTuOo7t0O4QAJ0ZfBWThtPuyXNA4peF7O7r xQRz+Ulew7QoiZ9nwtHQontm8J7htStmfgEFC3+tnpNGMdQuSuuegLbHoxza56Tf GQb3jtjM5s1WoJAhCAZaQR90152qHHd46On2dVXO3a9+Gc1CyMjYvrO1eJkscjF2 0g/Nw67TJGzt+T+JBg5eokP8Abd+tFgHQzptXIEhRVe08MWZonOMhqixqKSeM476 72ie66QR2PXv/pF8XlOOMDYw5wn+iIy8s05ZTXZNA4FwidxOcw5uBDqrhUyHup0x Dfv1mEREevsDq4pFVXQghKpzMRaROfFtmpn/c1KQbYvhEtDzZqXiEZ0JV3Vq2+ny qF9ooD/sotjeqULwWmnjSB3F9smUtf74OGHHlUUUzQqzFFxWNFej9gMs62uQsBv6 dG5wEt7Ugo0I12Et0l8rfdGgmrUuHd+8qnsf8XDCFIzzVkDEkM9qyyAjobvD7DgD q3piL9ioG1Gp2ug+vx60gZh2PXw/Acq0sdhr4Gj03pIgOsRy8wYM1ZcxdP6N1Hmu +Enqz8J1LY3fDMn/uN8/IDWHCV6SNAzGBEaRVtWkSmZ4rY8Mhls9whmcT/zOHf11 nmuMTl/C/VotTnucvbEA/fas2N5IoOsltNg8iM8WI3bUQ1DsSkcYLKziuYkqKcIq uDY6k9wl2hoi/o59O+Y4 =u5qr -----END PGP SIGNATURE----- --Apple-Mail=_3EB900CF-8B2A-4DCC-B7C7-3C0BC2BF7EEF--