Apple iTunes before 11.1.4 uses HTTP for the iTunes Tutorials window, which allows man-in-the-middle attackers to spoof content by gaining control over the client-server data stream.
| Software | From | Fixed in |
|---|---|---|
| apple / itunes | 11.1 | 11.1.x |
| apple / itunes | 11.0.4 | 11.0.4.x |
| apple / itunes | 11.0 | 11.0.x |
| apple / itunes | 11.0.1 | 11.0.1.x |
| apple / itunes | 11.1.2 | 11.1.2.x |
| apple / itunes | 11.0.5 | 11.0.5.x |
| apple / itunes | 11.0.3 | 11.0.3.x |
| apple / itunes | - | 11.1.3.x |
| apple / itunes | 11.1.1 | 11.1.1.x |
| apple / itunes | 11.0.2 | 11.0.2.x |