CVE Vulnerabilities

CVE-2014-1242

Published: Jan 23, 2014 | Modified: Aug 29, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Apple iTunes before 11.1.4 uses HTTP for the iTunes Tutorials window, which allows man-in-the-middle attackers to spoof content by gaining control over the client-server data stream.

Affected Software

Name Vendor Start Version End Version
Itunes Apple * 11.1.3 (including)
Itunes Apple 11.0 (including) 11.0 (including)
Itunes Apple 11.0.1 (including) 11.0.1 (including)
Itunes Apple 11.0.2 (including) 11.0.2 (including)
Itunes Apple 11.0.3 (including) 11.0.3 (including)
Itunes Apple 11.0.4 (including) 11.0.4 (including)
Itunes Apple 11.0.5 (including) 11.0.5 (including)
Itunes Apple 11.1 (including) 11.1 (including)
Itunes Apple 11.1.1 (including) 11.1.1 (including)
Itunes Apple 11.1.2 (including) 11.1.2 (including)

References