Wednesday
May282008
Apple ICal 3.0.1, DOS Attack
Wednesday, May 28, 2008 at 11:20AM
ICal 3.0.1 allows remote CalDav servers and user assisted remote attacker to allow for DOS attack. This can result in a system crash and the posiablilty of code execution. No log in is requiered to exploit this weakness. The client interact with the remote attacker in some manner. The user must import a .ICS file from teh attacker. Currently there is no fix for this attack, make sure that your users do not import in and .ICS file from someone they do not know.
Reader Comments