vendor:
iCal
by:
SecurityFocus
7.5
CVSS
HIGH
Integer-Overflow
190
CWE
Product Name: iCal
Affected Version From: iCal 3.0.1
Affected Version To: iCal 3.0.1
Patch Exists: YES
Related CWE: N/A
CPE: apple:ical
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Mac OS X 10.5.1
2007
Apple iCal Integer-Overflow Vulnerability
Apple iCal is prone to an integer-overflow vulnerability because it fails to ensure that integer values aren't overrun. An attacker can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
Mitigation:
Ensure that integer values are not overrun.