CVE-2016-5824: Use After Free
A vulnerability in the Libical libary used by Thunderbird can allow remote attackers to cause a denial of service (use-after-free) via a crafted ICS calendar file.
Other sources
A vulnerability in the Libical library used by Thunderbird can allow remote attackers to cause a denial of service (use-after-free) via a crafted ICS calendar file.
— Mozilla
libical 1.0 allows remote attackers to cause a denial of service (use-after-free) via a crafted ics file.
— Launchpad
Multiple use after free vulnerabilities possibly having the same root cause was found in libical.
Upstream bug:
https://bugzilla.mozilla.org/showbug.cgi?id=1275400
CVE assignment:
http://seclists.org/oss-sec/2016/q2/604
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2016-5824?
The severity of CVE-2016-5824 is medium with a severity value of 5.5.
Which software is affected by CVE-2016-5824?
Thunderbird (specifically version 60.5) and Libical library version 1.0 are affected by CVE-2016-5824.
How can I exploit CVE-2016-5824?
As a user, you do not need to exploit CVE-2016-5824. It is a vulnerability that can be exploited by remote attackers.
How can I fix CVE-2016-5824 in Thunderbird?
To fix CVE-2016-5824 in Thunderbird, update to version 60.5 or a later version.
Where can I find more information about CVE-2016-5824?
You can find more information about CVE-2016-5824 on Bugzilla and the Mozilla Security Advisories website.