CVE-2016-5826: High severity Libical Project Libical vulnerability
Published Jan 27, 2017
·Updated
The parsergetnextchar function in libical 0.47 and 1.0 allows remote attackers to cause a denial of service (out-of-bounds heap read) by crafting a string to the icalparserparsestring function.
Affected Software
2 affected components
Libical Project Libical=0.47
Libical Project Libical=1.0
Event History
Jan 27, 2017
CVE Published
via MITRE·10:01 PM
Data Sourced
via MITRE·10:01 PM
Description
Data Sourced
via NVD·10:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-5826?
CVE-2016-5826 has a severity rating of Medium due to its potential to cause denial of service.
2
How do I fix CVE-2016-5826?
To fix CVE-2016-5826, update libical to version 1.0 or later or apply relevant patches if available.
3
Which versions of libical are affected by CVE-2016-5826?
CVE-2016-5826 affects libical versions 0.47 and 1.0.
4
Can CVE-2016-5826 be exploited remotely?
Yes, CVE-2016-5826 can be exploited remotely by sending specially crafted strings to the affected service.
5
What type of vulnerability is CVE-2016-5826?
CVE-2016-5826 is a denial of service vulnerability caused by an out-of-bounds heap read.