APPLE-SA-2019-7-23-2 iTunes for Windows 12.9.6

Apple Product Security <[email protected]>
Newsgroups gmane.comp.security.bugtraq
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

APPLE-SA-2019-7-23-2 iTunes for Windows 12.9.6

iTunes for Windows 12.9.6 is now available and addresses the
following:

libxslt
Available for: Windows 7 and later
Impact: A remote attacker may be able to view sensitive information
Description: A stack overflow was addressed with improved input
validation.
CVE-2019-13118: found by OSS-Fuzz

WebKit
Available for: Windows 7 and later
Impact: Processing maliciously crafted web content may lead to
universal cross site scripting
Description: A logic issue was addressed with improved state
management.
CVE-2019-8658: akayn working with Trend Micro's Zero Day Initiative

WebKit
Available for: Windows 7 and later
Impact: Processing maliciously crafted web content may lead to
universal cross site scripting
Description: A logic issue existed in the handling of document loads.
This issue was addressed with improved state management.
CVE-2019-8690: Sergei Glazunov of Google Project Zero

WebKit
Available for: Windows 7 and later
Impact: Processing maliciously crafted web content may lead to
arbitrary code execution
Description: Multiple memory corruption issues were addressed with
improved memory handling.
CVE-2019-8644: G. Geshev working with Trend Micro's Zero Day
Initiative
CVE-2019-8666: Zongming Wang (王宗明) and Zhe Jin (金哲) from Chengdu
Security Response Center of Qihoo 360 Technology Co. Ltd.
CVE-2019-8669: akayn working with Trend Micro's Zero Day Initiative
CVE-2019-8671: Apple
CVE-2019-8672: Samuel Groß of Google Project Zero
CVE-2019-8673: Soyeon Park and Wen Xu of SSLab at Georgia Tech
CVE-2019-8676: Soyeon Park and Wen Xu of SSLab at Georgia Tech
CVE-2019-8677: Jihui Lu of Tencent KeenLab
CVE-2019-8678: an anonymous researcher, Anthony Lai (@darkfloyd1014)
of Knownsec, Ken Wong (@wwkenwong) of VXRL, Jeonghoon Shin
(@singi21a) of Theori, Johnny Yu (@straight_blast) of VX Browser
Exploitation Group, Chris Chan (@dr4g0nfl4me) of VX Browser
Exploitation Group, Phil Mok (@shadyhamsters) of VX Browser
Exploitation Group, Alan Ho (@alan_h0) of Knownsec, Byron Wai of VX
Browser Exploitation
CVE-2019-8679: Jihui Lu of Tencent KeenLab
CVE-2019-8680: Jihui Lu of Tencent KeenLab
CVE-2019-8681: G. Geshev working with Trend Micro Zero Day Initiative
CVE-2019-8683: lokihardt of Google Project Zero
CVE-2019-8684: lokihardt of Google Project Zero
CVE-2019-8685: akayn, Dongzhuo Zhao working with ADLab of Venustech,
Ken Wong (@wwkenwong) of VXRL, Anthony Lai (@darkfloyd1014) of VXRL,
and Eric Lung (@Khlung1) of VXRL
CVE-2019-8686: G. Geshev working with Trend Micro's Zero Day
Initiative
CVE-2019-8687: Apple
CVE-2019-8688: Insu Yun of SSLab at Georgia Tech
CVE-2019-8689: lokihardt of Google Project Zero

WebKit
Available for: Windows 7 and later
Impact: Processing maliciously crafted web content may lead to
universal cross site scripting
Description: A logic issue existed in the handling of synchronous
page loads. This issue was addressed with improved state management.
CVE-2019-8649: Sergei Glazunov of Google Project Zero

Installation note:

iTunes for Windows 12.9.6 may be obtained from:
https://www.apple.com/itunes/download/

Information will also be posted to the Apple Security Updates
web site: https://support.apple.com/kb/HT201222

This message is signed with Apple's Product Security PGP key,
and details are available at:
https://www.apple.com/support/security/pgp/
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEDNXJVNCJJEAVmJdZeC9tht7TK3EFAl03jEUACgkQeC9tht7T
K3GrFg//eiZAQhVCnq4ZtrobCgiGGs4bQE2sDC4zkjxH8CcamMPtCobvwNVZ9GV+
p66zWjSOlHI4L1/WS/EMIN381OHACMj8Qo7cfzc6gymT/UJYrbngn6YairxFUUQB
tJ+dLRpw8JN0K2DsU/gy1e4oqNc0ggf2CCW8sdkb1UjhqK2MderJzSNnXtUvZMA3
5BH4DRii/wk9btFBwE+ELUlF/H9zatOqiEslN/YzvSmmd/mUseobmGa+bQzoIKB7
dhvGkihHwdFHoVAqxlYdDgX30S4LKAqCAMJFXFti7I+8Nnf2iCbIeZOsUZyR//eT
TmIB05xsQu3EzNDr9CrigJ+nW2fWO+NlnWscIEtBClcenbIp4+7pCq7RMpB7zjFB
ocYJSOTytd1SNTgUt6wqhG1QbrpB1w6FSd6wm9DIb+T5/nwwv6fTCatMJ1gqisEu
Zma/aekjtBvX1dswqvGbpeT18W9c42xynWkR5AFTYTYQ2nZuaH+te+H5f9PazONa
hI2nPLI5/trKjN+pMn65MnU4K4/E6dbhBjeScXVRLUxSgck18xBVuSRVtcnAo0ZY
Le67HiOVmRIfTrljVbwLvbcSV6vUIikjIcPBDW4aSIRkizlxZAkB3Z9VVc93/g+A
XhE2wPIs8rZ7JU+LpDsyuh43ycziKf/99ViQvdTurie/3izu9po=
=x+8e
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.