-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 APPLE-SA-2018-10-30-6 iTunes 12.9.1 iTunes 12.9.1 is now available and addresses the following: CoreCrypto Available for: Windows 7 and later Impact: An attacker may be able to exploit a weakness in the Miller-Rabin primality test to incorrectly identify prime numbers Description: An issue existed in the method for determining prime numbers. This issue was addressed by using pseudorandom bases for testing of primes. CVE-2018-4398: Martin Albrecht, Jake Massimo and Kenny Paterson of Royal Holloway, University of London, and Juraj Somorovsky of Ruhr University, Bochum ICU Available for: Windows 7 and later Impact: Processing a maliciously crafted string may lead to heap corruption Description: A memory corruption issue was addressed with improved input validation. CVE-2018-4394: an anonymous researcher Safari Reader Available for: Windows 7 and later Impact: Enabling the Safari Reader feature on a maliciously crafted webpage may lead to universal cross site scripting Description: A logic issue was addressed with improved validation. CVE-2018-4374: Ryan Pickren (ryanpickren.com) Safari Reader Available for: Windows 7 and later Impact: Enabling the Safari Reader feature on a maliciously crafted webpage may lead to universal cross site scripting Description: A cross-site scripting issue existed in Safari. This issue was addressed with improved URL validation. CVE-2018-4377: Ryan Pickren (ryanpickren.com) WebKit Available for: Windows 7 and later Impact: Processing maliciously crafted web content may lead to arbitrary code execution Description: Multiple memory corruption issues were addressed with improved memory handling. CVE-2018-4372: HyungSeok Han, DongHyeon Oh, and Sang Kil Cha of KAIST Softsec Lab, Korea CVE-2018-4373: ngg, alippai, DirtYiCE, KT of Tresorit working with Trend Micro's Zero Day Initiative CVE-2018-4375: Yu Haiwan and Wu Hongjun From Nanyang Technological University working with Trend Micro's Zero Day Initiative CVE-2018-4376: 010 working with Trend Micro's Zero Day Initiative CVE-2018-4382: lokihardt of Google Project Zero CVE-2018-4386: lokihardt of Google Project Zero CVE-2018-4392: zhunki of 360 ESG Codesafe Team CVE-2018-4416: lokihardt of Google Project Zero WebKit Available for: Windows 7 and later Impact: A malicious website may be able to cause a denial of service Description: A resource exhaustion issue was addressed with improved input validation. CVE-2018-4409: Sabri Haddouche (@pwnsdx) of Wire Swiss GmbH WebKit Available for: Windows 7 and later Impact: Processing maliciously crafted web content may lead to code execution Description: A memory corruption issue was addressed with improved validation. CVE-2018-4378: an anonymous researcher, zhunki of 360 ESG Codesafe Team Installation note: iTunes 12.9.1 may be obtained from: https://www.apple.com/itunes/download/ Information will also be posted to the Apple Security Updates web site: https://support.apple.com/kb/HT201222 This message is signed with Apple's Product Security PGP key, and details are available at: https://www.apple.com/support/security/pgp/ -----BEGIN PGP SIGNATURE----- iQJdBAEBCABHFiEEDNXJVNCJJEAVmJdZeC9tht7TK3EFAlvYkgYpHHByb2R1Y3Qt c2VjdXJpdHktbm9yZXBseUBsaXN0cy5hcHBsZS5jb20ACgkQeC9tht7TK3GNOxAA jTN1Ef/XkeHTiQhAuO6+G2iBXaP4J9yxfUj+Spcmxp+DJOlKvQ4gKVZYk+LrxwIg tpGlItsRxc/xFCF0xCXvxFEAbKCi0fcjfCglxCkaRHO6Rv3cuR00P4fLlI0sCx3N HR22fdS+afraB+dszz9XNLNcEwSb/4kYBDe1cx053kooEiC7V1jBqWy2/G+oQJ4I DuKYQOn2e9Py0IYhPSVKoZeg5bHVohKsAB7o/gfvjKq76so5gEKud5pO9FZq2Kfg iO09Gz4OgFG2Xg8ztO2ek9u63AD/9O/Tx0T934TXNhDujt19pihTMn2zdf7sQig5 NyZJs862JXKGYJW46njsleG5Mh0LsE3+clzb15YMdYa9gHy97/l6qtk0PIJSExJp V0cNPK9QMDfYj7PNyG38P8OC8L8ljNG2BcdFXFQPSlXeqmQgcezlXgrK3LIunwP1 AxtfRLdO94ROuPC+BN0cYcOsLP1Xevpb78XSwxyJ/3ojoJ8InGEdpy2pl/jjEyqB c0uV80CZPWQ9KFjZqVkSuz5Mhte5MKgW04+P6gpRImhJ2nc3Liq23T83X536TsbV 0ELuOdqAbEa3A8lrPr5flj0LeHl43Zk86HSnlc2kmmY7bJZqGQ4MQdW2GTeqSHRg aen38sMzCh9nrURuvpI8CpVtJFTm7bWs7WCt22FHLTc= =mCVP -----END PGP SIGNATURE-----