Executive brief
libical is a widely used library for handling iCalendar data, often found in email clients like Thunderbird and calendar applications. A vulnerability in how it processes calendar files allows a remote attacker to crash applications using the library by sending a specially crafted calendar invitation or file. This results in a denial of service, potentially disrupting scheduling and communication services.
Technical details
An out-of-bounds heap read vulnerability exists in libical versions 0.47 and 1.0 within the icaltime_from_string function. The flaw is triggered when the icalparser_parse_string function processes a malformed iCalendar string, leading to a buffer over-read during time string conversion. A remote, unauthenticated attacker can exploit this by providing a specially crafted .ics file or string, causing the application to crash (denial of service). The issue was identified using AddressSanitizer (ASan) and affects components relying on libical for calendar parsing, such as the Mozilla Calendar (Lightning) extension.
Affected products
- libical project libical 0.47, 1.0
Timeline
- 2016-06-25: disclosed: Public disclosure on oss-security mailing list
- 2017-01-27: advisory: NVD publication date