MGASA-2018-0021
Dashboard / Vulnerabilities / MGASA-2018-0021
MGASA-2018-0021
Summary: Updated libical packages fix security vulnerability
Details: libical 1.0 allows remote attackers to cause a denial of service (use-after-free) via a crafted ics file (CVE-2016-5824). The icaltime_from_string function in libical 0.47 and 1.0 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted string to the icalparser_parse_string function (CVE-2016-5827). libical allows remote attackers to cause a denial of service (use-after-free) and possibly read heap memory via a crafted ics file (CVE-2016-9584).
References: https://advisories.mageia.org/MGASA-2018-0021.html, https://bugs.mageia.org/show_bug.cgi?id=21397, https://lists.opensuse.org/opensuse-updates/2017-07/msg00108.html
Affected packages
Package
Name: libical
Purl: pkg:rpm/mageia/libical?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
