Show plain JSON{"configurations": [{"nodes": [{"cpeMatch": [{"criteria": "cpe:2.3:a:apple:itunes:*:*:windows:*:*:*:*:*", "matchCriteriaId": "A57528B3-69F7-4B76-9B15-2CDA3220F4CC", "versionEndIncluding": "7.6.1", "vulnerable": true}, {"criteria": "cpe:2.3:a:apple:itunes:1.0:*:windows:*:*:*:*:*", "matchCriteriaId": "49DC3DDC-8758-4D28-B2D5-161994C0E669", "vulnerable": true}, {"criteria": "cpe:2.3:a:apple:itunes:1.1.1:*:windows:*:*:*:*:*", "matchCriteriaId": "0D0E3B53-AFAE-47F1-B7E3-395406819357", "vulnerable": true}, {"criteria": "cpe:2.3:a:apple:itunes:1.1.2:*:windows:*:*:*:*:*", "matchCriteriaId": "5CF3BB89-1AEF-4B00-AF87-C9BAF7E23EDD", "vulnerable": true}, {"criteria": "cpe:2.3:a:apple:itunes:2.0:*:windows:*:*:*:*:*", "matchCriteriaId": "389B617F-29D2-4171-B4E0-9E65BBFAF369", "vulnerable": true}, {"criteria": "cpe:2.3:a:apple:itunes:2.0.1:*:windows:*:*:*:*:*", "matchCriteriaId": "696D5986-155D-446C-A5FE-49C0DF1868AF", "vulnerable": true}, {"criteria": "cpe:2.3:a:apple:itunes:2.0.2:*:windows:*:*:*:*:*", "matchCriteriaId": "3370179D-5E8A-4036-AA23-252674C6D807", "vulnerable": true}, {"criteria": "cpe:2.3:a:apple:itunes:2.0.3:*:windows:*:*:*:*:*", "matchCriteriaId": "2B71E645-F15B-43FE-931B-819F9ABA89C0", "vulnerable": true}, {"criteria": "cpe:2.3:a:apple:itunes:2.0.4:*:windows:*:*:*:*:*", "matchCriteriaId": "E90B5E1A-4D90-4252-8E34-649F33F1A088", "vulnerable": true}, {"criteria": "cpe:2.3:a:apple:itunes:3.0:*:windows:*:*:*:*:*", "matchCriteriaId": "1D0D1162-36F7-4F7E-94C0-ABB86B9FC4CD", "vulnerable": true}, {"criteria": "cpe:2.3:a:apple:itunes:3.0.1:*:windows:*:*:*:*:*", "matchCriteriaId": "DF23791B-F73D-4CF4-BAC3-591FF0F0B0C6", "vulnerable": true}, {"criteria": "cpe:2.3:a:apple:itunes:4.0:*:windows:*:*:*:*:*", "matchCriteriaId": "3E74DB1C-208B-42DE-9A5E-E9010140C5B6", "vulnerable": true}, {"criteria": "cpe:2.3:a:apple:itunes:4.0.1:*:windows:*:*:*:*:*", "matchCriteriaId": "018AC033-ACF0-496D-96E1-A03CC4162CB3", "vulnerable": true}, {"criteria": "cpe:2.3:a:apple:itunes:4.1:*:windows:*:*:*:*:*", "matchCriteriaId": "A698DDBE-B79B-4F59-AFBC-0A0682B1EF1D", "vulnerable": true}, {"criteria": "cpe:2.3:a:apple:itunes:4.2:*:windows:*:*:*:*:*", "matchCriteriaId": "BC9B5471-F1B1-4E8B-B991-FDE231BA30EE", "vulnerable": true}, {"criteria": "cpe:2.3:a:apple:itunes:4.2.72:*:windows:*:*:*:*:*", "matchCriteriaId": "F2899F21-F01F-4C95-93AA-40C528EE56DF", "vulnerable": true}, {"criteria": "cpe:2.3:a:apple:itunes:4.5:*:windows:*:*:*:*:*", "matchCriteriaId": "BDD1695A-271B-4832-B4B1-E5A9D7DE4E24", "vulnerable": true}, {"criteria": "cpe:2.3:a:apple:itunes:4.6:*:windows:*:*:*:*:*", "matchCriteriaId": "9136E8D6-310D-4D4E-A6AC-2F89218B8666", "vulnerable": true}, {"criteria": "cpe:2.3:a:apple:itunes:4.7:*:windows:*:*:*:*:*", "matchCriteriaId": "78A3FEC0-F135-41F9-A260-52157B283B66", "vulnerable": true}, {"criteria": "cpe:2.3:a:apple:itunes:4.7.1:*:windows:*:*:*:*:*", "matchCriteriaId": "79591197-B671-46B2-9EB2-03A75A838CC1", "vulnerable": true}, {"criteria": "cpe:2.3:a:apple:itunes:4.7.1.30:*:windows:*:*:*:*:*", "matchCriteriaId": "A2DD1A9D-4AF4-452A-99C2-AE93611C985D", "vulnerable": true}, {"criteria": "cpe:2.3:a:apple:itunes:4.8:*:windows:*:*:*:*:*", "matchCriteriaId": "8DEABC06-3FF2-4B6A-AAFF-F38B00BA2967", "vulnerable": true}, {"criteria": "cpe:2.3:a:apple:itunes:4.9:*:windows:*:*:*:*:*", "matchCriteriaId": "6514E3F5-3B5D-43BE-A26D-5167B519F3EF", "vulnerable": true}, {"criteria": "cpe:2.3:a:apple:itunes:5.0:*:windows:*:*:*:*:*", "matchCriteriaId": "23C49853-8616-4769-90BC-B6D85B24A36E", "vulnerable": true}, {"criteria": "cpe:2.3:a:apple:itunes:5.0.1:*:windows:*:*:*:*:*", "matchCriteriaId": "7C1EC2F5-FBE8-4EC8-9D28-83C736F2DC01", "vulnerable": true}, {"criteria": "cpe:2.3:a:apple:itunes:6.0:*:windows:*:*:*:*:*", "matchCriteriaId": "8DDAAC1F-03CA-4DCC-9E9B-A68181261BAC", "vulnerable": true}, {"criteria": "cpe:2.3:a:apple:itunes:6.0.1:*:windows:*:*:*:*:*", "matchCriteriaId": "D5AE8F59-2DF8-403B-BAB9-6465E618897C", "vulnerable": true}, {"criteria": "cpe:2.3:a:apple:itunes:6.0.2:*:windows:*:*:*:*:*", "matchCriteriaId": "F37B39AB-2D5B-417E-BCEF-29C18D386C53", "vulnerable": true}, {"criteria": "cpe:2.3:a:apple:itunes:6.0.3:*:windows:*:*:*:*:*", "matchCriteriaId": "A1DCEED8-8174-4319-BAA2-E0A70A7EAFC0", "vulnerable": true}, {"criteria": "cpe:2.3:a:apple:itunes:6.0.4:*:windows:*:*:*:*:*", "matchCriteriaId": "9730866D-DFE9-448F-9D4E-6B21B3942737", "vulnerable": true}, {"criteria": "cpe:2.3:a:apple:itunes:6.0.4.2:*:windows:*:*:*:*:*", "matchCriteriaId": "E20BC99A-13FC-446C-A27A-6C2D859C172B", "vulnerable": true}, {"criteria": "cpe:2.3:a:apple:itunes:6.0.5:*:windows:*:*:*:*:*", "matchCriteriaId": "DD300F1B-EE8F-4606-B024-A14CA2EF4D78", "vulnerable": true}, {"criteria": "cpe:2.3:a:apple:itunes:7.0.2:*:windows:*:*:*:*:*", "matchCriteriaId": "2690D789-B1DC-40A5-8CC6-BBB499E9A550", "vulnerable": true}, {"criteria": "cpe:2.3:a:apple:itunes:7.3.2:*:windows:*:*:*:*:*", "matchCriteriaId": "BC37C091-02B8-4B39-9253-52C1008ADEC6", "vulnerable": true}, {"criteria": "cpe:2.3:a:apple:itunes:7.4:*:windows:*:*:*:*:*", "matchCriteriaId": "70A4EEE2-1DD2-4936-8939-4683523670B9", "vulnerable": true}, {"criteria": "cpe:2.3:a:apple:itunes:7.4.1:*:windows:*:*:*:*:*", "matchCriteriaId": "95B58CD1-03CB-4C35-A290-7157941D210D", "vulnerable": true}, {"criteria": "cpe:2.3:a:apple:itunes:7.4.2:*:windows:*:*:*:*:*", "matchCriteriaId": "A27B736F-317F-4538-AA3B-72D6EF0D2D33", "vulnerable": true}, {"criteria": "cpe:2.3:a:apple:itunes:7.4.3:*:windows:*:*:*:*:*", "matchCriteriaId": "481E736B-0A83-4422-B1D3-4BD0F9565A18", "vulnerable": true}, {"criteria": "cpe:2.3:a:apple:itunes:7.5:*:windows:*:*:*:*:*", "matchCriteriaId": "3BB09ABD-C1F1-4101-BDC2-FC3E8C422631", "vulnerable": true}, {"criteria": "cpe:2.3:a:apple:itunes:7.6:*:windows:*:*:*:*:*", "matchCriteriaId": "A7448F89-CC4A-4B18-887F-B47C0B57404C", "vulnerable": true}, {"criteria": "cpe:2.3:a:apple:itunes:7.6.2:*:windows:*:*:*:*:*", "matchCriteriaId": "B2943C2E-0DDD-498A-9439-E9394CB06081", "vulnerable": true}, {"criteria": "cpe:2.3:a:apple:itunes:7.7:*:windows:*:*:*:*:*", "matchCriteriaId": "D41DA19A-4403-40A8-A3DB-01A12FD4F267", "vulnerable": true}, {"criteria": "cpe:2.3:a:apple:itunes:7.7.1:*:windows:*:*:*:*:*", "matchCriteriaId": "25E7EF0A-D79E-44E3-B0D4-3C6E8F6FD666", "vulnerable": true}], "negate": false, "operator": "OR"}]}], "cveTags": [], "descriptions": [{"lang": "en", "value": "Integer overflow in the IopfCompleteRequest API in the kernel in Microsoft Windows 2000, XP, Server 2003, and Vista allows context-dependent attackers to gain privileges. NOTE: this issue was originally reported for GEARAspiWDM.sys 2.0.7.5 in Gear Software CD DVD Filter driver before 4.001.7, as used in other products including Apple iTunes and multiple Symantec and Norton products, which allows local users to gain privileges via repeated IoAttachDevice IOCTL calls to \\\\.\\GEARAspiWDMDevice in this GEARAspiWDM.sys. However, the root cause is the integer overflow in the API call itself."}, {"lang": "es", "value": "Desbordamiento de entero en un driver de terceros no especificado incluido en Apple iTunes anterior a la 8.0 para Windows, permite a usuarios locales obtener privilegios a trav\u00e9s de vectores desconocidos."}], "id": "CVE-2008-3636", "lastModified": "2025-04-09T00:30:58.490", "metrics": {"cvssMetricV2": [{"acInsufInfo": false, "baseSeverity": "HIGH", "cvssData": {"accessComplexity": "LOW", "accessVector": "LOCAL", "authentication": "NONE", "availabilityImpact": "COMPLETE", "baseScore": 7.2, "confidentialityImpact": "COMPLETE", "integrityImpact": "COMPLETE", "vectorString": "AV:L/AC:L/Au:N/C:C/I:C/A:C", "version": "2.0"}, "exploitabilityScore": 3.9, "impactScore": 10.0, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": false}]}, "published": "2008-09-11T01:13:10.023", "references": [{"source": "cve@mitre.org", "url": "http://lists.apple.com/archives/security-announce//2008/Sep/msg00001.html"}, {"source": "cve@mitre.org", "url": "http://securityresponse.symantec.com/avcenter/security/Content/2008.10.07a.html"}, {"source": "cve@mitre.org", "url": "http://securitytracker.com/id?1020839"}, {"source": "cve@mitre.org", "url": "http://support.apple.com/kb/HT3025"}, {"source": "cve@mitre.org", "url": "http://www.gearsoftware.com/support/GEARAspi%20Security%20Information.pdf"}, {"source": "cve@mitre.org", "tags": ["US Government Resource"], "url": "http://www.kb.cert.org/vuls/id/146896"}, {"source": "cve@mitre.org", "url": "http://www.securityfocus.com/archive/1/497131/100/0/threaded"}, {"source": "cve@mitre.org", "tags": ["Patch"], "url": "http://www.securityfocus.com/bid/31089"}, {"source": "cve@mitre.org", "url": "http://www.securitytracker.com/id?1020997"}, {"source": "cve@mitre.org", "url": "http://www.securitytracker.com/id?1020998"}, {"source": "cve@mitre.org", "url": "http://www.securitytracker.com/id?1020999"}, {"source": "cve@mitre.org", "url": "http://www.symantec.com/avcenter/security/Content/2008.10.07a.html"}, {"source": "cve@mitre.org", "url": "http://www.vupen.com/english/advisories/2008/2526"}, {"source": "cve@mitre.org", "url": "http://www.vupen.com/english/advisories/2008/2769"}, {"source": "cve@mitre.org", "url": "http://www.vupen.com/english/advisories/2008/2770"}, {"source": "cve@mitre.org", "url": "http://www.wintercore.com/advisories/advisory_W021008.html"}, {"source": "cve@mitre.org", "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6035"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://lists.apple.com/archives/security-announce//2008/Sep/msg00001.html"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://securityresponse.symantec.com/avcenter/security/Content/2008.10.07a.html"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://securitytracker.com/id?1020839"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://support.apple.com/kb/HT3025"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://www.gearsoftware.com/support/GEARAspi%20Security%20Information.pdf"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["US Government Resource"], "url": "http://www.kb.cert.org/vuls/id/146896"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://www.securityfocus.com/archive/1/497131/100/0/threaded"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Patch"], "url": "http://www.securityfocus.com/bid/31089"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://www.securitytracker.com/id?1020997"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://www.securitytracker.com/id?1020998"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://www.securitytracker.com/id?1020999"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://www.symantec.com/avcenter/security/Content/2008.10.07a.html"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://www.vupen.com/english/advisories/2008/2526"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://www.vupen.com/english/advisories/2008/2769"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://www.vupen.com/english/advisories/2008/2770"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://www.wintercore.com/advisories/advisory_W021008.html"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6035"}], "sourceIdentifier": "cve@mitre.org", "vulnStatus": "Deferred", "weaknesses": [{"description": [{"lang": "en", "value": "CWE-189"}], "source": "nvd@nist.gov", "type": "Primary"}]}