Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-5827

Опубликовано: 27 янв. 2017
Источник: debian
EPSS Низкий

Описание

The icaltime_from_string function in libical 0.47 and 1.0 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted string to the icalparser_parse_string function.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libicalremovedpackage
libicalignoredstretchpackage
libicalno-dsajessiepackage
libicalno-dsawheezypackage

Примечания

  • https://bugzilla.mozilla.org/show_bug.cgi?id=1281043

  • This issue fixed by the commits referenced via https://github.com/libical/libical/issues/251

  • https://github.com/libical/libical/commit/38757abb495ea6cb40faa5418052278bf75040f7

  • https://github.com/libical/libical/commit/04d84749e53db08c71ed0ce8b6ba5c11082743cd

  • https://github.com/libical/libical/commit/830d9530817516377c2bc3b532798ce2c6b4765a

EPSS

Процентиль: 73%
0.00759
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 9 лет назад

The icaltime_from_string function in libical 0.47 and 1.0 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted string to the icalparser_parse_string function.

CVSS3: 7.5
redhat
больше 9 лет назад

The icaltime_from_string function in libical 0.47 and 1.0 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted string to the icalparser_parse_string function.

CVSS3: 7.5
nvd
около 9 лет назад

The icaltime_from_string function in libical 0.47 and 1.0 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted string to the icalparser_parse_string function.

CVSS3: 7.5
github
больше 3 лет назад

The icaltime_from_string function in libical 0.47 and 1.0 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted string to the icalparser_parse_string function.

suse-cvrf
больше 8 лет назад

Security update for libical

EPSS

Процентиль: 73%
0.00759
Низкий