May 21, 2008 11:43 AM PDT

Apple iCal hit with three remote vulnerabilities

On Wednesday, Core Security announced three vulnerabilities within iCal, the personal calendar application that ships with the Mac operating system. The vulnerabilities affect iCal version 3.0.1 on MacOS X 10.5.1.

ZDNet's Ryan Naraine quotes an as-yet unpublished Core Security announcement as saying: "The vulnerabilities are caused due to iCal not properly sanitizing certain fields on iCal calendar files (.ics). This can be possibly exploited to crash iCal (first two bugs) or possibly execute arbitrary code (third bug) via malicious calendar updates or by importing a specially crafted calendar file."

Apple was rumored to be releasing a large security patch later on Wednesday, but, in an update to his blog, Naraine says that will not happen. In the meantime, Leopard users should be suspicious of links and e-mails with requests to add/open calendar (.ics) files.

Recent posts from Defense in Depth
Column: Raising Cain at Black Hat
Black Hat 2008: Notes from the field
Column: Finally, ID fraud protection that works
Column: Will you be ditching your antivirus app anytime soon?
A real simple answer to password protection
Add a Comment (Log in or register) 12 comments (Page 1 of 1)
by iertry May 21, 2008 12:02 PM PDT
Why is this such a problem? It effects 10.5.1 but Apple has already released 10.5.2 (I'm using it now I just checked) and they are testing 10.5.3

Unless 10.5.1 is a typo this is already fixed is it not?
Reply to this comment
by Elidine May 21, 2008 12:42 PM PDT
Apple is nothing more than a proprietary kick in the nuts. I would never buy Crapple. Ever. I run a successful computer business and I will never sell Crapple products. Crapple?s OS is garbage, its Ipods, Iphones, and Ibooks all suck.

Who would want to waste their time hacking an OS that so few people use? No one, that?s why there aren?t more attacks. Period.
Reply to this comment View all 5 replies
by TiMMay333 May 21, 2008 2:50 PM PDT
And people take what you say seriously? With your childish remarks, you seem like a 13 year old fan boy. Very Sad
Reply to this comment
by TiMMay333 May 21, 2008 2:53 PM PDT
Way to go CNET, lets make people that own a mac nervous about an exploit that's already been fixed... i hope people realize, especially if your reading a security site, that updating your OS is esential, even if you run a mac.
Reply to this comment
by another_dan May 21, 2008 4:58 PM PDT
this is a Zero_Day_exploit? that's what ZDNet called it.
i would guess that most folks running Leopard would already have updated to OS 10.5.2 and iCal 3.0.2. i know i did a few months ago, or whenever that was. hard to remember.
Reply to this comment
by brunerd May 21, 2008 10:49 PM PDT
Well let's say you are a Digidesign Pro-Tools user you can't use 10.5.2 because it broke things that were fixed in 10.5.1? That's one very plausible and actual scenario. Not everyone in a production environment can leap at the newest. What I really think should be mentioned is how "rigged websites" can be used because of that one little checkbox in Safari prefs that says "Open 'Safe' files after downloading" -- what an awful decision. Unless you believe all known exploitable bugs have been fixed in OS X, keep yourself safe from a drive-by download and make sure you turn it off.
Reply to this comment
by Elidine May 22, 2008 5:00 AM PDT
It really doesn't bother me if you think I'm childish. My opinions are my own, and they haven't caused me to lose any business.

I thought to be a fanboy you had to like the product? (hence the fan part)

Using apple is like "going green", it just doesn't make sense.
Reply to this comment
Powered by Jive Software
advertisement
  • About Defense in Depth

  • Covering computer viruses and computer crime, Robert Vamosi goes beyond the hype to provide you with expert interviews of the top security researchers, as well as offering the hands-on, nontechnical advice you'll need to stay safe online.

Add this feed to your online news reader
Google
Yahoo
MSN

Latest tech news headlines

Featured blogs

Beyond Binary by Ina Fried

Coop's Corner by Charles Cooper

Defense in Depth by Robert Vamosi

Geek Gestalt by Daniel Terdiman

Green Tech

One More Thing by Tom Krazit

Outside the Lines by Dan Farber

The Iconoclast by Declan McCullagh

The Social by Caroline McCarthy

Underexposed by Stephen Shankland

Resource center from News.com sponsors
Same great protection. Reengineered for speed.
Norton Internet Security™2008

Click Here!
Norton still delivers award-winning protection and now uses 83% less memory and scans 48% faster than the competitor average. Get a FREE trial today!

Click Here!
Norton Beats the Competition

See how Norton Internet Security™2008 uses less memory, while scanning and booting faster than the competitor average.

Norton Protection Blog

Read the latest from our security experts as they help protect people from evolving online threats.

Protect Your Bluetooth Connection

Don't let fraudsters sink their teeth into your Bluetooth connection.

Vishing - What you need to know

Meet the latest ID theft scam: Voice Phishing.

Take Norton for a Test Drive Today!

Act now to get your FREE trial of Norton Internet Security 2008.

advertisement
On last.fm: Find and Listen to Music You Like
Advanced
search
Advanced
search
Visit other CBS Interactive sites