iCal Remote Buffer Overflow Vulnerability
BID:6506
Info
iCal Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 6506 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 03 2003 12:00AM |
| Updated: | Jan 03 2003 12:00AM |
| Credit: | Discovery of this vulnerability credited to securma massine <[email protected]>. |
| Vulnerable: |
Brown Bear Software iCal 3.7 |
| Not Vulnerable: | |
Discussion
iCal Remote Buffer Overflow Vulnerability
A buffer overflow vulnerability has been reported for iCal. The vulnerability occurs when the iCal web server receives an overly long HTTP request. This will cause iCal to crash and result in a denial of service condition.
Restarting the service is necessary to restore functionality.
A buffer overflow vulnerability has been reported for iCal. The vulnerability occurs when the iCal web server receives an overly long HTTP request. This will cause iCal to crash and result in a denial of service condition.
Restarting the service is necessary to restore functionality.
Exploit / POC
iCal Remote Buffer Overflow Vulnerability
The following proof of concept was provided:
nc target 80
AAAA
The following proof of concept was provided:
nc target 80
AAAA
Solution / Fix
iCal Remote Buffer Overflow Vulnerability
Solution:
The vendor has supplied an update that is reported to address this vulnerability:
Brown Bear Software iCal 3.7
Solution:
The vendor has supplied an update that is reported to address this vulnerability:
Brown Bear Software iCal 3.7
-
Brown Bear Software iCal 3.8
Vendor upgrade instrctions:http://www.brownbearsw.com/ical/icalupgrade.html
http://www.brownbearsoftware.com/ical/icalv38.exe
References
iCal Remote Buffer Overflow Vulnerability
References:
References:
- iCal Upgrade Instructions (Brown Bear Software)
- Product Page (Brown Bear Software)
- ical 3.7 remote dos (securma massine
)