Thursday, April 29, 2021

Apple Security Advisory 2021-04-26-9

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

APPLE-SA-2021-04-26-9 iTunes 12.11.3 for Windows

iTunes 12.11.3 for Windows addresses the following issues.
Information about the security content is also available at
https://support.apple.com/HT212319.

CFNetwork
Available for: Windows 10 and later
Impact: Processing maliciously crafted web content may disclose
sensitive user information
Description: A memory initialization issue was addressed with
improved memory handling.
CVE-2021-1857: an anonymous researcher

CoreText
Available for: Windows 10 and later
Impact: Processing a maliciously crafted font may result in the
disclosure of process memory
Description: A logic issue was addressed with improved state
management.
CVE-2021-1811: Xingwei Lin of Ant Security Light-Year Lab

WebKit
Available for: Windows 10 and later
Impact: Processing maliciously crafted web content may lead to a
cross site scripting attack
Description: An input validation issue was addressed with improved
input validation.
CVE-2021-1825: Alex Camboe of Aon’s Cyber Solutions

WebRTC
Available for: Windows 10 and later
Impact: A remote attacker may be able to cause unexpected system
termination or corrupt kernel memory
Description: A use after free issue was addressed with improved
memory management.
CVE-2020-7463: Megan2013678

Installation note:

This update may be obtained from: https://www.apple.com/itunes/download

Additional recognition

CoreCrypto
We would like to acknowledge Andy Russon of Orange Group for their
assistance.

Information will also be posted to the Apple Security Updates
web site: https://support.apple.com/kb/HT201222

This message is signed with Apple's Product Security PGP key,
and details are available at:
https://www.apple.com/support/security/pgp/

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEbURczHs1TP07VIfuZcsbuWJ6jjAFAmCHO44ACgkQZcsbuWJ6
jjArzRAAldgXX1lo6Y4ka3jXfPbXfAoX9lJkSlMu/W/mURmjfbs9cWRPp645AX61
QU09meDWVHMNpPKYwFh1G2Tuq7c8WjtPRshnEYn7LpRW4ViF//UBys0T3k0w6pw5
bSEFFRaXViBpN761eDARxnVTgeWShTD89JJt4VWtYBc/DK6+le20+XhJB7A9sUET
QJqR1rjAimZOwm9mEkfzkXpq0y5mKMagGcuxBZs4mAuUZD28gytLWiYz5yb9LhQK
0eYdhDtxVHQB/sto++NGa4oxGlKK7r3Uo4ICAUegOFmbkYpYO2t0tlt/hvlIoJgx
sn6XpEbOsCMpmBZfIkFfLlWxuV6TFJ+3fZbTYuyuq65ytkGAVsRGe3PUIzq0mVfV
eM1QbKCOJ+Evt8T6IfkVBlmi6ggG02A4tTR9Hf7i4JSsqNnd+hlZXQ3VwFUWe4/n
jfhmllz6GwJiTFN28bK6iO8EB9ITqTMc6GH9SgQxXA/7T4BNNSNWzxVRDSJLgPS4
sS2QmHqRoniOIraD8aIiqnajhXI1S5Q4/KF+bkGZNFNfxznEEUTsoLhUvXYqnA43
PLEkCTAOhrVWCZ18fw9B2C2J8fPm6KRnv8ER6svsnf2X9dV8pQwWiIn8kva2EPOV
7dPXBK+vp/jGAYDXhy0m5FIanped7dhJPa2Hg5xYAHXEjHLB+BA=
=w/gh
-----END PGP SIGNATURE-----


 

Copyright © 2021 Vulnerability Database | Cyber Details™

thank you Templateism for the design - You should have written the code a little more complicated - Nothing Encrypted anymore