vendor:
iCal
by:
SecurityFocus
7.5
CVSS
HIGH
Denial-of-Service
20
CWE
Product Name: iCal
Affected Version From: iCal 3.0.1
Affected Version To: Other versions may also be affected.
Patch Exists: N/A
Related CWE: N/A
CPE: apple:ical
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2007
Apple iCal Denial-of-Service Vulnerability
Apple iCal is prone to a denial-of-service vulnerability because it fails to adequately sanitize user-supplied input data. Successful exploits will crash the application. Given the nature of this issue, attackers may also be able to run arbitrary code, but this has not been confirmed.
Mitigation:
Input validation should be used to ensure that user-supplied data is properly sanitized.