Denial of Service in Apple iCal on Mac OS X
CVE-2008-2006

Currently unrated

Key Information:

Vendor

Apple

Status
Vendor
CVE Published:
22 May 2008

What is CVE-2008-2006?

Apple iCal version 3.0.1 on Mac OS X is susceptible to a denial of service attack triggered by specially crafted .ics files. Attackers can manipulate content within the TRIGGER line by inserting large 16-bit integers or provide excessive values in the COUNT field on an RRULE line. This can lead to a NULL pointer dereference, causing the application to crash or potentially allowing the execution of arbitrary code if executed in a specific manner. Users of iCal should be cautious while handling .ics files from untrusted sources.

References

EPSS Score

32% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.