CVE-2016-9584: Use After Free
Published Jan 18, 2017
·Updated
libical allows remote attackers to cause a denial of service (use-after-free) and possibly read heap memory via a crafted ics file.
Affected Software
1 affected component
Libical Project Libical<=2.0
Event History
Jan 18, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
via NVD·05:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-9584?
CVE-2016-9584 is classified as a medium-severity vulnerability due to its potential for denial of service.
2
How can I fix CVE-2016-9584?
To fix CVE-2016-9584, upgrade to the latest version of libical that addresses this vulnerability.
3
What is the impact of CVE-2016-9584?
CVE-2016-9584 allows remote attackers to cause a denial of service and possibly access sensitive heap memory.
4
What software is affected by CVE-2016-9584?
CVE-2016-9584 affects libical versions up to and including 2.0.
5
How does CVE-2016-9584 exploit a crafted ICS file?
CVE-2016-9584 exploits a use-after-free condition when processing a specially crafted ICS file.