iCal Software for Mac Finds 3 Security Flaws: Apple Users Beware

by mac52ipod on 2008-05-26 08:29:44

Three security vulnerabilities have been found in Apple's iCal calendar application. Hackers could take advantage of these vulnerabilities to cause the application to crash or execute code remotely on the victim's Mac computer.

Core Security released a security bulletin earlier this week that detailed the vulnerabilities. These affect iCal 3.0.1 running on Mac OS X 10.5.1.

The bulletin warned that the most serious of the three flaws was caused by a memory corruption issue resulting from a flaw in the way resource files are handled. The potential attacker could exploit this via a specially-crafted malicious '.ics' calendar file.