>> Apple iCal Memory Corruption and Denial of Service Vulnerabilities
Title : Apple iCal Memory Corruption and Denial of Service Vulnerabilities VUPEN ID : VUPEN/ADV-2008-1601 CVE ID : CVE-2008-1035 - CVE-2008-2006 - CVE-2008-2007
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-05-21
Technical Description
Multiple vulnerabilities have been identified in Apple iCal, which could be exploited by attackers to cause a denial of service or potentially compromise a vulnerable system. These issues are caused by NULL pointer derefence and memory corruption errors when processing ICS files containing a malformed "COUNT", "TRIGGER" or "ATTACH" field, which could be exploited by attackers to crash an affected application or potentially execute arbitrary code by tricking a user into opening a specially crafted file.