CVE-2008-3434

Apple iTunes before 10.5.1 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
appleitunes
𝑥
≤ 6.0.5
appleitunes
1.0
appleitunes
1.1
appleitunes
1.1.1
appleitunes
1.1.2
appleitunes
2.0
appleitunes
2.0.1
appleitunes
2.0.2
appleitunes
2.0.3
appleitunes
2.0.4
appleitunes
3.0
appleitunes
3.0.1
appleitunes
4.0
appleitunes
4.0.1
appleitunes
4.1
appleitunes
4.2
appleitunes
4.5
appleitunes
4.6
appleitunes
4.7
appleitunes
4.7.1
appleitunes
4.8
appleitunes
4.9
appleitunes
5.0
appleitunes
5.0.1
appleitunes
6.0
appleitunes
6.0.1
appleitunes
6.0.2
appleitunes
6.0.3
appleitunes
6.0.4
appleitunes
6.0.4.2
𝑥
= Vulnerable software versions