-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 APPLE-SA-2019-5-28-1 iTunes for Windows 12.9.5 iTunes for Windows 12.9.5 is now available and addresses the following: SQLite Available for: Windows 7 and later Impact: An application may be able to gain elevated privileges Description: An input validation issue was addressed with improved memory handling. CVE-2019-8577: Omer Gull of Checkpoint Research SQLite Available for: Windows 7 and later Impact: A maliciously crafted SQL query may lead to arbitrary code execution Description: A memory corruption issue was addressed with improved input validation. CVE-2019-8600: Omer Gull of Checkpoint Research SQLite Available for: Windows 7 and later Impact: A malicious application may be able to read restricted memory Description: An input validation issue was addressed with improved input validation. CVE-2019-8598: Omer Gull of Checkpoint Research SQLite Available for: Windows 7 and later Impact: A malicious application may be able to elevate privileges Description: A memory corruption issue was addressed by removing the vulnerable code. CVE-2019-8602: Omer Gull of Checkpoint Research WebKit Available for: Windows 7 and later Impact: Processing maliciously crafted web content may result in the disclosure of process memory Description: An out-of-bounds read was addressed with improved input validation. CVE-2019-8607: Junho Jang and Hanul Choi of LINE Security Team WebKit Available for: Windows 7 and later Impact: Processing maliciously crafted web content may lead to arbitrary code execution Description: Multiple memory corruption issues were addressed with improved memory handling. CVE-2019-6237: G. Geshev working with Trend Micro Zero Day Initiative, Liu Long of Qihoo 360 Vulcan Team CVE-2019-8571: 01 working with Trend Micro's Zero Day Initiative CVE-2019-8583: sakura of Tencent Xuanwu Lab, jessica (@babyjess1ca_) of Tencent Keen Lab, and dwfault working at ADLab of Venustech CVE-2019-8584: G. Geshev of MWR Labs working with Trend Micro Zero Day Initiative CVE-2019-8586: an anonymous researcher CVE-2019-8587: G. Geshev working with Trend Micro Zero Day Initiative CVE-2019-8594: Suyoung Lee and Sooel Son of KAIST Web Security & Privacy Lab and HyungSeok Han and Sang Kil Cha of KAIST SoftSec Lab CVE-2019-8595: G. Geshev from MWR Labs working with Trend Micro Zero Day Initiative CVE-2019-8596: Wen Xu of SSLab at Georgia Tech CVE-2019-8597: 01 working with Trend Micro Zero Day Initiative CVE-2019-8601: Fluoroacetate working with Trend Micro's Zero Day Initiative CVE-2019-8608: G. Geshev working with Trend Micro Zero Day Initiative CVE-2019-8609: Wen Xu of SSLab, Georgia Tech CVE-2019-8610: Anonymous working with Trend Micro Zero Day Initiative CVE-2019-8611: Samuel Groß of Google Project Zero CVE-2019-8615: G. Geshev from MWR Labs working with Trend Micro's Zero Day Initiative CVE-2019-8619: Wen Xu of SSLab at Georgia Tech and Hanqing Zhao of Chaitin Security Research Lab CVE-2019-8622: Samuel Groß of Google Project Zero CVE-2019-8623: Samuel Groß of Google Project Zero CVE-2019-8628: Wen Xu of SSLab at Georgia Tech and Hanqing Zhao of Chaitin Security Research Lab Installation note: iTunes for Windows 12.9.5 may be obtained from: https://www.apple.com/itunes/download/ Information will also be posted to the Apple Security Updates web site: https://support.apple.com/kb/HT201222 This message is signed with Apple's Product Security PGP key, and details are available at: https://www.apple.com/support/security/pgp/ -----BEGIN PGP SIGNATURE----- iQJdBAEBCABHFiEEDNXJVNCJJEAVmJdZeC9tht7TK3EFAlztSiMpHHByb2R1Y3Qt c2VjdXJpdHktbm9yZXBseUBsaXN0cy5hcHBsZS5jb20ACgkQeC9tht7TK3G1dg// a6GThIoRgS6Aox/EJPxVULE3RsxaRNug9Cn/33Xw10aJhOEhBLtx6702XlSYQhUX SwJiB8sLFetvRmDRDcO/d3MY64sUDNTY1CRvtg65+9I0JrmkyTMd5VBxF6ZvScG6 yUPCF1S8aaLZzImhIcSlzWMVtPZKxxkKaHHDNNH9ewPWa3iPRAd9YhoXrd+FElUD OrfFkCcVxYGRjONIHUhRWKbxyulRBP7tUjCLfjwZyo0rpgqMPKdqMjP8Ew1j3QVe bf90tB/7UpjSR5c8yTb9eO+4MZm/qZl+7GcQkjdNy6STfA2mZNX62E9VHElqDbrg 4MqqXsMKx9gB3YnyPaxKQZUfSdFP/Ou0S08SDHGGqDkFmkGXopPxl+bCtHg0UEwg Mbo5x9m3f27uTIu2llrkjlKL0xnKQBWChvgl0OMwjm40bGMy2hcA/nLNLNwCzUti uKnMELe46IOlum8iLYtaRrrwvX1Afi9t8F2spBh1XyrrxF6yAn9JyJeCrB+ZQsE8 gYstJ/pl+zSkHv3q97bdLALAiCXjHnPB/dqwJad+0l7VcvC61nnuXuFF9gB6b7qx 5Bt5Lgsac1RrjkSmC+Bn+2Y/9iviOV+yzqKSPqd16mcmJaqe+IYxXB2cIY2xPAYI ph9+Vi8ElG9eSifTFL0c3D8MhWX/hLllsitdQC2q4ow= =8R3n -----END PGP SIGNATURE-----