CVE-2016-5827: High severity Libical Project Libical vulnerability
Published Jan 27, 2017
·Updated
The icaltimefromstring function in libical 0.47 and 1.0 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted string to the icalparserparsestring function.
Affected Software
2 affected components
Libical Project Libical=0.47
Libical Project Libical=1.0.0
Event History
Jan 27, 2017
CVE Published
via MITRE·10:01 PM
Data Sourced
via MITRE·10:01 PM
Description
Data Sourced
via NVD·10:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-5827?
The severity of CVE-2016-5827 is classified as a denial of service vulnerability.
2
How do I fix CVE-2016-5827?
To fix CVE-2016-5827, upgrade libical to version 1.0.1 or later where the vulnerability is patched.
3
What versions of libical are affected by CVE-2016-5827?
CVE-2016-5827 affects libical versions 0.47 and 1.0.0.
4
What kind of attack does CVE-2016-5827 allow?
CVE-2016-5827 allows remote attacks leading to a denial of service via an out-of-bounds heap read.
5
Is CVE-2016-5827 related to string parsing?
Yes, CVE-2016-5827 is related to the processing of crafted strings in the icalparser_parse_string function.