MGASA-2018-0021

Advisory lineage Upstream: 3 Downstream: 0
Published: 02 Jan 2018, 16:25
Last modified:16 Apr 2026, 06:26

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

02 Jan 2018, 16:25
Published
Vulnerability first disclosed
16 Apr 2026, 06:26
Last Modified
Vulnerability information updated

Description

Updated libical packages fix security vulnerability libical 1.0 allows remote attackers to cause a denial of service (use-after-free) via a crafted ics file (CVE-2016-5824). The icaltime_from_string function in libical 0.47 and 1.0 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted string to the icalparser_parse_string function (CVE-2016-5827). libical allows remote attackers to cause a denial of service (use-after-free) and possibly read heap memory via a crafted ics file (CVE-2016-9584).

Affected Systems

  • mageialibical

    < 1.0-4.1.mga5

  • mageialibical

    < 2.0.0-2.1.mga6

References (3)