Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 492
Alerts This Week
Warning Icon 1 492

Debian 7 Wheezy: DLA-959-1 Critical Use-After-Free in Libical

debian lts
Calendar Grey May 28, 2017
Scroller Debian Lts
Update libical to block exploitation that could lead to denial of service and potential exposure of heap memory due to specially crafted .ICS files in Debian 7 Wheezy.
It was discovered that there was a use-after-free vulnerability in the libical iCalendar library

Summary

For Debian 7 "Wheezy", this issue has been fixed in libical version
0.48-2+deb7u1.

We recommend that you upgrade your libical packages.


Regards,

- --
,'`.
: :' : Chris Lamb
`. `'` lamby@debian.org / chris-lamb.co.uk
`-



Severity
critical
Lowest
Low
Medium
High
Critical

Package: libical
Version: 0.48-2+deb7u1
CVE ID: CVE-2016-5824 CVE-2016-9584
Debian Bug: #860451, #852034

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.