CVE-2008-1035
Apple iCal 3.0.1 - Use-After-Free via Malformed CalDAV ATTACH Line
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-1035. PoCs published by Core Security Technologies.
AI-analyzed exploit summary This is a proof-of-concept exploit for CVE-2008-1035, targeting a denial-of-service vulnerability in Apple iCal. The exploit uses a malformed .ics file with crafted calendar data to crash the application.
Description
Use-after-free vulnerability in Apple iCal 3.0.1 on Mac OS X allows remote CalDAV servers, and user-assisted remote attackers, to trigger memory corruption or possibly execute arbitrary code via an "ATTACH;VALUE=URI:S=osumi" line in a .ics file, which triggers a "resource liberation" bug. NOTE: CVE-2008-2007 was originally used for this issue, but this is the appropriate identifier.
Exploits (1)
This is a proof-of-concept exploit for CVE-2008-1035, targeting a denial-of-service vulnerability in Apple iCal. The exploit uses a malformed .ics file with crafted calendar data to crash the application.