A security firm has identified serious vulnerabilities in Apple’s iCal calendar application. Core Security Technologies reports that it discovered three vulnerabilities in the application, which could enable an attacker to execute arbitrary code or launch a denial of service attack.
The most serious of the vulnerabilities stems from “potential memory corruption” from a bug that attackers can take advantage of with a specially crafted malformed .ics calendar file, Core said.
The other two vulnerabilities lead to crashes of iCal due to “null-pointer dereference bugs triggered while parsing a malformed .ics files,” the firm said. Core researched but did not ultimately prove that it was possible to inject arbitrary code onto vulnerable systems using these methods.
“Exploitation of these vulnerabilities in a client-side attack scenario is possible with user assistance by opening or clicking on specially crafted .ics file sent over email or hosted on a malicious web server; or without direct user assistance if a would-be attacker has the ability to legitimately add or modify calendar files on a CalDAV server,” Core said.
The security posting includes a long log file of Core’s interactions with Apple over this security issue. Apple requested several extensions of the publication date of the report and Core evinced frustration with delays. Core first notified Apple of the flaws in January and the companies debated the severity of the flaws in a series of messages over several months. Apple said that it would release a security fix on May 19 but as that date passed without a release, Core published its report on Wednesday.
It’s not uncommon for security firms to be frustrated with vendors, said Andrews Storms, director of security operations for nCircle Network Security.
“When researchers publicly disclose their timelines and communications with
vendors on security issues, rarely do we find compassion for the vendor,” Storms wrote…