Apple iCal 'TRIGGER' Parameter Denial of Service Vulnerability
BID:28632
Info
Apple iCal 'TRIGGER' Parameter Denial of Service Vulnerability
| Bugtraq ID: | 28632 |
| Class: | Design Error |
| CVE: |
CVE-2008-2006 |
| Remote: | Yes |
| Local: | No |
| Published: | May 21 2008 12:00AM |
| Updated: | May 21 2008 10:24PM |
| Credit: | Rodrigo Carvalho from the Core Security Consulting Services (CSC) team of Core Security Technologies |
| Vulnerable: |
Apple iCal 3.0.1 |
| Not Vulnerable: | |
Discussion
Apple iCal 'TRIGGER' Parameter Denial of Service Vulnerability
Apple iCal is prone to a denial-of-service vulnerability because it fails to handle specially crafted files.
An attacker can exploit this issue to crash the affected application, denying service to legitimate users.
This issue affects iCal 3.0.1 running on Mac OS X 10.5.1; previous versions may also be affected.
Apple iCal is prone to a denial-of-service vulnerability because it fails to handle specially crafted files.
An attacker can exploit this issue to crash the affected application, denying service to legitimate users.
This issue affects iCal 3.0.1 running on Mac OS X 10.5.1; previous versions may also be affected.
Exploit / POC
Apple iCal 'TRIGGER' Parameter Denial of Service Vulnerability
To exploit this issue, an attacker must entice an unsuspecting user to import a malicious ICS file.
The following ICS file is available to trigger this issue:
To exploit this issue, an attacker must entice an unsuspecting user to import a malicious ICS file.
The following ICS file is available to trigger this issue:
Solution / Fix
Apple iCal 'TRIGGER' Parameter Denial of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Apple iCal 'TRIGGER' Parameter Denial of Service Vulnerability
References:
References:
- Mac OS X Homepage (Apple)
- Multiple vulnerabilities in iCal (Core Security Technologies)