CVE-2016-5825: Medium severity Libical Project Libical vulnerability
Published Jan 27, 2017
·Updated
The icalparserparsestring function in libical 0.47 and 1.0 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted ics file.
Affected Software
2 affected components
Libical Project Libical=0.47
Libical Project Libical=1.0
Event History
Jan 27, 2017
CVE Published
via MITRE·10:01 PM
Data Sourced
via MITRE·10:01 PM
Description
Data Sourced
via NVD·10:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-5825?
CVE-2016-5825 has a severity rating of medium due to the potential for denial of service.
2
How do I fix CVE-2016-5825?
To fix CVE-2016-5825, upgrade to libical version 1.1 or later.
3
What is the impact of CVE-2016-5825?
The impact of CVE-2016-5825 includes the potential for an out-of-bounds heap read leading to denial of service.
4
Which versions of libical are affected by CVE-2016-5825?
CVE-2016-5825 affects libical versions 0.47 and 1.0.
5
Can CVE-2016-5825 be exploited remotely?
Yes, CVE-2016-5825 can be exploited remotely using a crafted ICS file.