3901Third-party advisory
http://securityreason.com/securityalert/3901 CVE-2008-2006
Apple iCal 3.0.1 - 'COUNT' Integer Overflow
Record summary
CVE-2008-2006 has a selected CVSS score of 4.3; EIP currently links 2 catalogued exploits.
Description
Apple iCal 3.0.1 on Mac OS X allows remote CalDAV servers, and user-assisted remote attackers, to cause a denial of service (NULL pointer dereference and application crash) or possibly execute arbitrary code via a .ics file containing (1) a large 16-bit integer on a TRIGGER line, or (2) a large integer in a COUNT field on an RRULE line.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 2
Proofs of concept
2Catalogued exploits
ExploitDBApple iCal 3.0.1 - 'COUNT' Integer OverflowExploitDB exploitby Core Security TechnologiesNot analyzed1 file
ExploitDBApple iCal 3.0.1 - 'TRIGGER' Denial of ServiceExploitDB exploitby Rodrigo CarvalhoNot analyzed1 file
References
11coresecurity.com
http://www.coresecurity.com/?action=item&id=2219 20080521 CORE-2008-0126: Multiple vulnerabilities in iCalmailing list
http://www.securityfocus.com/archive/1/492414/100/0/threaded 20080527 Re: CORE-2008-0126: Multiple vulnerabilities in iCalmailing list
http://www.securityfocus.com/archive/1/492638/100/100/threaded 20080528 Re: CORE-2008-0126: Multiple vulnerabilities in iCalmailing list
http://www.securityfocus.com/archive/1/492682/100/0/threaded 28629vdb entry
http://www.securityfocus.com/bid/28629 28632vdb entry
http://www.securityfocus.com/bid/28632 1020094vdb entry
http://www.securitytracker.com/id?1020094 ADV-2008-1601vdb entry
http://www.vupen.com/english/advisories/2008/1601 ical-trigger-dos(42569)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/42569 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2008-2006