Executive brief
libical is a widely used software library for handling calendar data (iCalendar). A vulnerability in how it processes calendar files could allow an attacker to crash applications that use this library, such as email clients or scheduling software, by sending a specially crafted calendar (.ics) file. This results in a denial of service, potentially disrupting user schedules and communication tools.
Technical details
A use-after-free vulnerability exists in the icalproperty_new_clone function within libical versions 0.47, 1.0, and potentially others prior to 3.0.0. The flaw is triggered when the library processes a malformed iCalendar (.ics) file, leading to a segmentation fault (SEGV) or memory corruption. While the NVD classifies the attack vector as local with user interaction (opening a file), the practical application in mail clients or servers often makes this reachable via remote delivery of malicious attachments. An attacker can exploit this to cause a denial of service (application crash). The issue was addressed in libical version 3.0.0.
Affected products
- libical project libical 0.47, 1.0, and all versions prior to 3.0.0
Timeline
- 2016-06-25: disclosed: Public disclosure on oss-security mailing list
- 2017-01-27: advisory: NVD publication date
- 2019-04-02: patched: Gentoo security advisory indicates version 3.0.0 as unaffected