Unrated severityNVD Advisory· Published Aug 1, 2008· Updated Apr 23, 2026
CVE-2008-3434
CVE-2008-3434
Description
Apple iTunes before 10.5.1 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.
Affected products
30cpe:2.3:a:apple:itunes:1.1.1:*:*:*:*:*:*:*+ 29 more
- cpe:2.3:a:apple:itunes:1.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:apple:itunes:1.1.2:*:*:*:*:*:*:*
- cpe:2.3:a:apple:itunes:2.0:*:*:*:*:*:*:*
- cpe:2.3:a:apple:itunes:2.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:apple:itunes:2.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:apple:itunes:2.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:apple:itunes:2.0.4:*:*:*:*:*:*:*
- cpe:2.3:a:apple:itunes:*:*:*:*:*:*:*:*range: <=6.0.5
- cpe:2.3:a:apple:itunes:1.0:*:*:*:*:*:*:*
- cpe:2.3:a:apple:itunes:1.1:*:*:*:*:*:*:*
- cpe:2.3:a:apple:itunes:3.0:*:*:*:*:*:*:*
- cpe:2.3:a:apple:itunes:3.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:apple:itunes:4.0:*:*:*:*:*:*:*
- cpe:2.3:a:apple:itunes:4.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:apple:itunes:4.1:*:*:*:*:*:*:*
- cpe:2.3:a:apple:itunes:4.2:*:*:*:*:*:*:*
- cpe:2.3:a:apple:itunes:4.5:*:*:*:*:*:*:*
- cpe:2.3:a:apple:itunes:4.6:*:*:*:*:*:*:*
- cpe:2.3:a:apple:itunes:4.7:*:*:*:*:*:*:*
- cpe:2.3:a:apple:itunes:4.7.1:*:*:*:*:*:*:*
- cpe:2.3:a:apple:itunes:4.8:*:*:*:*:*:*:*
- cpe:2.3:a:apple:itunes:4.9:*:*:*:*:*:*:*
- cpe:2.3:a:apple:itunes:5.0:*:*:*:*:*:*:*
- cpe:2.3:a:apple:itunes:5.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:apple:itunes:6.0:*:*:*:*:*:*:*
- cpe:2.3:a:apple:itunes:6.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:apple:itunes:6.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:apple:itunes:6.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:apple:itunes:6.0.4:*:*:*:*:*:*:*
- cpe:2.3:a:apple:itunes:6.0.4.2:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- archives.neohapsis.com/archives/bugtraq/2008-07/0250.htmlnvd
- lists.apple.com/archives/Security-announce/2011/Nov/msg00003.htmlnvd
- support.apple.com/kb/HT5030nvd
- www.infobyte.com.ar/down/Francisco%20Amato%20-%20evilgrade%20-%20ENG.pdfnvd
- www.infobyte.com.ar/down/isr-evilgrade-1.0.0.tar.gznvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17136nvd
News mentions
0No linked articles in our index yet.