About the security content of iTunes 10.5.1
This document describes the security content of iTunes 10.5.1.
For the protection of our customers, Apple does not disclose, discuss or confirm security issues until a full investigation has occurred and any necessary patches or releases are available. To find out more about Apple Product Security, see the Apple Product Security website.
For information about the Apple Product Security PGP Key, see "How to use the Apple Product Security PGP Key."
Where possible, CVE IDs are used to reference the vulnerabilities for further information.
To find out about other Security Updates, see "Apple Security Updates".
iTunes 10.5.1
iTunes
Available for: Mac OS X v10.5 or later, Windows 7, Vista, XP SP2 or later
Impact: A man-in-the-middle attacker may offer software that appears to originate from Apple
Description: iTunes periodically checks for software updates using an HTTP request to Apple. This request may cause iTunes to indicate that an update is available. If Apple Software Update for Windows is not installed, clicking the Download iTunes button may open the URL from the HTTP response in the user’s default browser. This issue has been mitigated by using a secured connection when checking for available updates. For OS X systems, the user’s default browser is not used because Apple Software Update is included with OS X, however this change adds additional defence-in-depth.
CVE-ID
CVE-2008-3434: Francisco Amato of Infobyte Security Research