PT-2008-3527 · Apple · Ical
Published
2008-05-22
·
Updated
2018-10-11
·
CVE-2008-2006
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Apple iCal version 3.0.1
Description
The issue allows remote CalDAV servers and user-assisted remote attackers to cause a denial of service or possibly execute arbitrary code. This can be achieved via a .ics file containing a large 16-bit integer on a
TRIGGER line, or a large integer in a COUNT field on an RRULE line.Recommendations
For Apple iCal version 3.0.1, consider avoiding the use of .ics files from untrusted sources until a patch is available. As a temporary workaround, restrict the handling of
TRIGGER and RRULE lines in .ics files to minimize the risk of exploitation.Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ical