CVE-2008-1035
Apple iCal 3.0.1 - 'ATTACH' Denial of Service
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
Use-after-free vulnerability in Apple iCal 3.0.1 on Mac OS X allows remote CalDAV servers, and user-assisted remote attackers, to trigger memory corruption or possibly execute arbitrary code via an "ATTACH;VALUE=URI:S=osumi" line in a .ics file, which triggers a "resource liberation" bug. NOTE: CVE-2008-2007 was originally used for this issue, but this is the appropriate identifier.
Una vulnerabilidad de uso de la memoria previamente liberada en Apple iCal versión 3.0.1 en Mac OS X, permite a los servidores CalDAV remotos y atacantes remotos asistidos por el usuario activar una corrupción de memoria o posiblemente ejecutar un código arbitrario mediante una línea "ATTACH;VALUE=URI:S=osumi" en un archivo .ics, que desencadena un bug de "resource liberation". NOTA: CVE-2008-2007 fue usado originalmente para este problema, pero este es el identificador apropiado.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2008-02-26 CVE Reserved
- 2008-04-21 First Exploit
- 2008-06-03 CVE Published
- 2024-08-07 CVE Updated
- 2025-01-21 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-94: Improper Control of Generation of Code ('Code Injection')
CAPEC
References (14)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/30430 | Third Party Advisory | |
http://www.securityfocus.com/archive/1/492414/100/0/threaded | Mailing List | |
http://www.securityfocus.com/archive/1/492638/100/100/threaded | Mailing List | |
http://www.securityfocus.com/archive/1/492682/100/0/threaded | Mailing List | |
http://www.securityfocus.com/bid/28633 | Vdb Entry | |
http://www.securityfocus.com/bid/29412 | Vdb Entry | |
http://www.securityfocus.com/bid/29486 | Vdb Entry | |
http://www.securitytracker.com/id?1020095 | Vdb Entry | |
http://www.us-cert.gov/cas/techalerts/TA08-150A.html | Third Party Advisory | |
http://www.vupen.com/english/advisories/2008/1601 | Vdb Entry | |
http://www.vupen.com/english/advisories/2008/1697 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/31620 | 2008-04-21 | |
http://www.coresecurity.com/?action=item&id=2219 | 2024-08-07 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://lists.apple.com/archives/security-announce/2008//May/msg00001.html | 2018-10-11 |