iCal Malformed HTTP Request Denial Of Service Vulnerability
BID:6505
Info
iCal Malformed HTTP Request Denial Of Service Vulnerability
| Bugtraq ID: | 6505 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 03 2003 12:00AM |
| Updated: | Jan 03 2003 12:00AM |
| Credit: | Discovery of this vulnerability credited to securma massine <[email protected]>. |
| Vulnerable: |
Brown Bear Software iCal 3.7 |
| Not Vulnerable: | |
Discussion
iCal Malformed HTTP Request Denial Of Service Vulnerability
A denial of service vulnerability has been reported for iCal. The vulnerability occurs when iCal receives a specially formatted HTTP request. This will cause iCal to crash thereby leading to a denial of service.
Restarting the service is necessary to restore functionality.
A denial of service vulnerability has been reported for iCal. The vulnerability occurs when iCal receives a specially formatted HTTP request. This will cause iCal to crash thereby leading to a denial of service.
Restarting the service is necessary to restore functionality.
Exploit / POC
iCal Malformed HTTP Request Denial Of Service Vulnerability
The following proof of concept was provided:
http//target/*
The following proof of concept was provided:
http//target/*
Solution / Fix
iCal Malformed HTTP Request Denial Of Service Vulnerability
Solution:
The vendor has supplied an update that is reported to address this vulnerability:
Brown Bear Software iCal 3.7
Solution:
The vendor has supplied an update that is reported to address this vulnerability:
Brown Bear Software iCal 3.7
-
Brown Bear Software iCal 3.8
Vendor upgrade instrctions:http://www.brownbearsw.com/ical/icalupgrade.html
http://www.brownbearsoftware.com/ical/icalv38.exe
References
iCal Malformed HTTP Request Denial Of Service Vulnerability
References:
References:
- iCal Upgrade Instructions (Brown Bear Software)
- Product Page (Brown Bear Software)
- ical 3.7 remote dos (securma massine
)