Apple released Apple TV 1.1 Software to implement YouTube.com Access and fix Security Issue
The security issue is:
CVE-2007-2386--A remote attacker may be able to cause a denial of service or arbitrary code execution. A buffer overflow vulnerability exists in the UPnP IGD (Internet Gateway Device Standardized Device Control Protocol) code used to create Port Mappings on home NAT gateways in the Apple TV implementation. By sending a maliciously crafted packet, a remote attacker can trigger the overflow which may lead to an unexpected application termination or arbitrary code execution. This update addresses the issue by performing additional validation when processing UPnP protocol packets. Credit to Michael Lynn of Juniper Networks for reporting this issue.
[Bill Fox]
Saw something? Send a tip
The archive ran on reader tips. What did you see, where, and do you want the credit?