Use-after-free vulnerability in Apple iCal affecting Mac OS X
CVE-2008-1035

Currently unrated

Key Information:

Vendor

Apple

Status
Vendor
CVE Published:
3 June 2008

What is CVE-2008-1035?

A use-after-free vulnerability in Apple iCal version 3.0.1 on Mac OS X can be exploited by remote CalDAV servers and user-assisted attackers. By crafting a malicious .ics file that includes the line 'ATTACH;VALUE=URI:S=osumi', an attacker can trigger memory corruption, potentially leading to the execution of arbitrary code on the victim's system. This vulnerability highlights the importance of diligent file handling and security measures against crafted inputs.

References

EPSS Score

16% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.