Junglewise Threat Intelligence

CVE-2016-5827: libical out-of-bounds read in icaltime_from_string

CVE-2016-5827 · Severity: high · CVSS 7.5 · Published 2017-01-27

Technologies: Libical Project Libical. Vendors: Libical Project.

Executive brief

libical is a widely used library for handling iCalendar data, often found in email clients like Thunderbird and calendar applications. A vulnerability in how it processes calendar files allows a remote attacker to crash applications using the library by sending a specially crafted calendar invitation or file. This results in a denial of service, potentially disrupting scheduling and communication services.

Technical details

An out-of-bounds heap read vulnerability exists in libical versions 0.47 and 1.0 within the icaltime_from_string function. The flaw is triggered when the icalparser_parse_string function processes a malformed iCalendar string, leading to a buffer over-read during time string conversion. A remote, unauthenticated attacker can exploit this by providing a specially crafted .ics file or string, causing the application to crash (denial of service). The issue was identified using AddressSanitizer (ASan) and affects components relying on libical for calendar parsing, such as the Mozilla Calendar (Lightning) extension.

Affected products

  • libical project libical 0.47, 1.0

Timeline

  • 2016-06-25: disclosed: Public disclosure on oss-security mailing list
  • 2017-01-27: advisory: NVD publication date

References

Related threats