Record summary

CVE-2008-1035 has a selected CVSS score of 4.3; EIP currently links 1 catalogued exploit.

Description

Use-after-free vulnerability in Apple iCal 3.0.1 on Mac OS X allows remote CalDAV servers, and user-assisted remote attackers, to trigger memory corruption or possibly execute arbitrary code via an "ATTACH;VALUE=URI:S=osumi" line in a .ics file, which triggers a "resource liberation" bug. NOTE: CVE-2008-2007 was originally used for this issue, but this is the appropriate identifier.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBApple iCal 3.0.1 - 'ATTACH' Denial of ServiceExploitDB exploitby Core Security TechnologiesNot analyzed1 file
ExploitDB

PoC details

References

Showing 12 of 14