Apple iTunes before 11.1.4 uses HTTP for the iTunes Tutorials window, which allows man-in-the-middle attackers to spoof content by gaining control over the client-server data stream.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Itunes | Apple | * | 11.1.3 (including) |
Itunes | Apple | 11.0 (including) | 11.0 (including) |
Itunes | Apple | 11.0.1 (including) | 11.0.1 (including) |
Itunes | Apple | 11.0.2 (including) | 11.0.2 (including) |
Itunes | Apple | 11.0.3 (including) | 11.0.3 (including) |
Itunes | Apple | 11.0.4 (including) | 11.0.4 (including) |
Itunes | Apple | 11.0.5 (including) | 11.0.5 (including) |
Itunes | Apple | 11.1 (including) | 11.1 (including) |
Itunes | Apple | 11.1.1 (including) | 11.1.1 (including) |
Itunes | Apple | 11.1.2 (including) | 11.1.2 (including) |