{ "id": "CVE-2007-1008", "sourceIdentifier": "cve@mitre.org", "published": "2007-02-20T01:28:00.000", "lastModified": "2018-10-16T16:36:22.890", "vulnStatus": "Modified", "evaluatorImpact": "Successful exploitation requires that an attacker perform some type of DNS spoofing or man-in-the-middle attack prior to launching this attack.", "descriptions": [ { "lang": "en", "value": "Apple iTunes 7.0.2 allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted XML list of radio stations, which results in memory corruption. NOTE: iTunes retrieves the XML document from a static URL, which requires an attacker to perform DNS spoofing or man-in-the-middle attacks for exploitation." }, { "lang": "es", "value": "Apple iTunes 7.0.2 permite a atacantes remotos con la intervenci\u00f3n el usuario provocar una denegaci\u00f3n de servicio (cierre de aplicaci\u00f3n) mediante una lista XML manipulada de estaciones de radio, lo cual provoca una corrupci\u00f3n de memoria. NOTA: iTunes obtiene el documento XML de una URL est\u00e1tica, lo cual requiere que un atacante realice una suplantaci\u00f3n de DNS o un ataque de hombre-en-medio (man-in-the-middle) para la explotaci\u00f3n." } ], "metrics": { "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:H/Au:N/C:N/I:N/A:P", "accessVector": "NETWORK", "accessComplexity": "HIGH", "authentication": "NONE", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "PARTIAL", "baseScore": 2.6 }, "baseSeverity": "LOW", "exploitabilityScore": 4.9, "impactScore": 2.9, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": true } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "NVD-CWE-Other" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:apple:itunes:7.0.2:*:*:*:*:*:*:*", "matchCriteriaId": "6FEE6DEC-9B26-47F4-A2CF-CA49981C8864" } ] } ] } ], "references": [ { "url": "http://osvdb.org/33742", "source": "cve@mitre.org" }, { "url": "http://securityreason.com/securityalert/2278", "source": "cve@mitre.org" }, { "url": "http://www.securityfocus.com/archive/1/460544/100/0/threaded", "source": "cve@mitre.org" }, { "url": "http://www.securityfocus.com/bid/22615", "source": "cve@mitre.org", "tags": [ "Exploit" ] }, { "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16978", "source": "cve@mitre.org" } ] }