Apple heeft versie 12.9.2 van iTunes uitgebracht. Met dit programma is het onder andere mogelijk om muziek te beluisteren of films en tv-series te bekijken. Deze kunnen via de internetmuziekwinkel van Apple iTunes worden aangeschaft. Het programma kan verder cd's branden en worden gebruikt om een iPod, iPhone of iPad te beheren. Apples iTunes is beschikbaar voor Windows 7 en nieuwer. Versie 12.9.2 moet diverse beveiligingsproblemen verhelpen.
iTunes 12.9.2 for Windows
SafariSafari
- Available for: Windows 7 and later
- Impact: Visiting a malicious website may lead to address bar spoofing
- Description: A logic issue was addressed with improved state management.
- CVE-2018-4440: Wenxu Wu of Tencent Security Xuanwu Lab (xlab.tencent.com)
WebKit
- Available for: Windows 7 and later
- Impact: Visiting a malicious website may lead to user interface spoofing
- Description: A logic issue was addressed with improved validation.
- CVE-2018-4439: xisigr of Tencent's Xuanwu Lab (tencent.com)
WebKit
- Available for: Windows 7 and later
- Impact: Processing maliciously crafted web content may lead to arbitrary code execution
- Description: Multiple memory corruption issues were addressed with improved memory handling.
- CVE-2018-4437: HyungSeok Han, DongHyeon Oh, and Sang Kil Cha of KAIST Softsec Lab, Korea
- CVE-2018-4464: HyungSeok Han, DongHyeon Oh, and Sang Kil Cha of KAIST Softsec Lab, Korea
WebKit
- Available for: Windows 7 and later
- Impact: Processing maliciously crafted web content may lead to arbitrary code execution
- Description: A memory corruption issue was addressed with improved memory handling.
- CVE-2018-4441: lokihardt of Google Project Zero
- CVE-2018-4442: lokihardt of Google Project Zero
- CVE-2018-4443: lokihardt of Google Project Zero
- Available for: Windows 7 and later
- Impact: Processing maliciously crafted web content may lead to arbitrary code execution
- Description: A logic issue existed resulting in memory corruption. This was addressed with improved state management.
- CVE-2018-4438: lokihardt of Google Project Zero
