Posted by Stefan Kanthak on Oct 24
Hi @ll,
the just released iTunes 12.0.1 for Windows still (cf.
<http://seclists.org/fulldisclosure/2014/Jul/30>) comes
with COMPLETELY outdated and VULNERAEBLE 3rd party libraries
(as part of AppleMobileDeviceSupport.msi):
* libeay32.dll and ssleay32.dll 0.9.8d
are more than SEVEN years old and have at least 27 unfixed CVEs!
* libcurl.dll 7.16.2
is more than SEVEN years old and has at least 18 unfixed CVEs!
the current version…