-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 APPLE-SA-2017-09-25-8 iTunes 12.7 for Windows iTunes 12.7 for Windows addresses the following: WebKit Available for: Windows 7 and later Impact: Processing maliciously crafted web content may lead to arbitrary code execution Description: A memory corruption issue was addressed through improved input validation. CVE-2017-7081: Apple Entry added September 25, 2017 WebKit Available for: Windows 7 and later Impact: Processing maliciously crafted web content may lead to arbitrary code execution Description: Multiple memory corruption issues were addressed with improved memory handling. CVE-2017-7087: Apple CVE-2017-7091: Wei Yuan of Baidu Security Lab working with Trend Microas Zero Day Initiative CVE-2017-7092: Qixun Zhao (@S0rryMybad) of Qihoo 360 Vulcan Team, Samuel Gro and Niklas Baumstark working with Trend Micro's Zero Day Initiative CVE-2017-7093: Samuel Gro and Niklas Baumstark working with Trend Microas Zero Day Initiative CVE-2017-7094: Tim Michaud (@TimGMichaud) of Leviathan Security Group CVE-2017-7095: Wang Junjie, Wei Lei, and Liu Yang of Nanyang Technological University working with Trend Microas Zero Day Initiative CVE-2017-7096: Wei Yuan of Baidu Security Lab CVE-2017-7098: Felipe Freitas of Instituto TecnolA3gico de AeronA!utica CVE-2017-7099: Apple CVE-2017-7100: Masato Kinugawa and Mario Heiderich of Cure53 CVE-2017-7102: Wang Junjie, Wei Lei, and Liu Yang of Nanyang Technological University CVE-2017-7104: likemeng of Baidu Secutity Lab CVE-2017-7107: Wang Junjie, Wei Lei, and Liu Yang of Nanyang Technological University CVE-2017-7111: likemeng of Baidu Security Lab (xlab.baidu.com) working with Trend Micro's Zero Day Initiative CVE-2017-7117: lokihardt of Google Project Zero CVE-2017-7120: chenqin (ee|) of Ant-financial Light-Year Security Lab Entry added September 25, 2017 WebKit Available for: Windows 7 and later Impact: Cookies belonging to one origin may be sent to another origin Description: A permissions issue existed in the handling of web browser cookies. This issue was addressed by no longer returning cookies for custom URL schemes. CVE-2017-7090: Apple Entry added September 25, 2017 WebKit Available for: Windows 7 and later Impact: Processing maliciously crafted web content may lead to a cross site scripting attack Description: Application Cache policy may be unexpectedly applied. CVE-2017-7109: avlidienbrunn Entry added September 25, 2017 Installation note: iTunes 12.7 for Windows may be obtained from: https://www.apple.com/itunes/download/ Information will also be posted to the Apple Security Updates web site: https://support.apple.com/kb/HT201222 This message is signed with Apple's Product Security PGP key, and details are available at: https://www.apple.com/support/security/pgp/ -----BEGIN PGP SIGNATURE----- Comment: GPGTools - https://gpgtools.org iQIcBAEBCgAGBQJZyUQgAAoJEIOj74w0bLRGxhsP+wXSLgL1JbHxZxzEPyBIy40Q As9yvCfyy9l1edhsjji9HWfsyV7voJMnSYu21jrfc+oiw85AhLyWAP0pqzZVaO/k XQZQYJJ70lQj9gP9PHJxVOGJhbE7vhC/80JA2ckPGKIA5+8bWY69klh7N1Ks871Z YrzCe32LNxtV5tCWpF60utOpbDudz5BtTS4vC5xJa6o5+M6kjhaF/AFb0FqeI8VM hmeyABpuz+KSp7zTUEW2f2JxmTJ4pIkfMA2ttJypnA4k07j4lO7c7CHZNP6PpbCX aoNq431BaN7UH9Bb25o5UXK/74PbSRP5WDamL99M6YvHYSmM/du0gDosXUvBxo5R 0qn+HkfR9QskfMDb3PxFo6OfZnFzHa9AjZ8cRewB+BOAyBOVMlLM4b0Rr0yhkjiG L3TDGFpbykxYaHN096xP3J4M0MvYihSFXSkXWL9b6mwCfQuBtRU+ChI8rUecbY13 +7BY5O9l6/mNxBQh7jvR+JwP2QWNb+6ioDLjKjorw9AV17tMZTX5tuvq5+rAEoYt u0m9arhWvjftOufHN9gaLJrjfdl9TueesydjlXtIzITBZ14vuzt1ykbZXt0kqCrJ V8yRvaKYQKCB2hF5hrqpWmTdJ7rOu5Es9l9xZz+0C9JXPtDIpk3ayzXHc9D9+BRk 9hJGdstIhzalhaMSDyEa =Usys -----END PGP SIGNATURE-----