Junglewise Threat Intelligence

CVE-2016-5823: libical use-after-free in icalproperty_new_clone

CVE-2016-5823 · Severity: medium · CVSS 5.5 · Published 2017-01-27

Technologies: Libical Project Libical. Vendors: Libical Project.

Executive brief

libical is a widely used software library for handling calendar data (iCalendar). A vulnerability in how it processes calendar files could allow an attacker to crash applications that use this library, such as email clients or scheduling software, by sending a specially crafted calendar (.ics) file. This results in a denial of service, potentially disrupting user schedules and communication tools.

Technical details

A use-after-free vulnerability exists in the icalproperty_new_clone function within libical versions 0.47, 1.0, and potentially others prior to 3.0.0. The flaw is triggered when the library processes a malformed iCalendar (.ics) file, leading to a segmentation fault (SEGV) or memory corruption. While the NVD classifies the attack vector as local with user interaction (opening a file), the practical application in mail clients or servers often makes this reachable via remote delivery of malicious attachments. An attacker can exploit this to cause a denial of service (application crash). The issue was addressed in libical version 3.0.0.

Affected products

  • libical project libical 0.47, 1.0, and all versions prior to 3.0.0

Timeline

  • 2016-06-25: disclosed: Public disclosure on oss-security mailing list
  • 2017-01-27: advisory: NVD publication date
  • 2019-04-02: patched: Gentoo security advisory indicates version 3.0.0 as unaffected

References

Related threats