CVE-2009-0143 Information
Feb 14, 2021
cve
Description
Apple iTunes before 8.1 does not properly inform the user about the origin of an authentication request which makes it easier for remote podcast servers to trick a user into providing a username and password when subscribing to a crafted podcast.
Reference
http://lists.apple.com/archives/security-announce//2009/Mar/msg00001.html http://osvdb.org/52579 http://secunia.com/advisories/34254 http://securitytracker.com/id?1021843 http://support.apple.com/kb/HT3487 http://www.securityfocus.com/bid/34094 http://www.vupen.com/english/advisories/2009/0702 https://exchange.xforce.ibmcloud.com/vulnerabilities/49201 https://oval.cisecurity.org/repository/search/definition/oval3Aorg.mitre.oval3Adef3A5336
Share on: