Bug#852034: libical: CVE-2016-9584: heap use-after-free

2017-04-16 Thread Salvatore Bonaccorso
Hi Since it looks that http://www.openwall.com/lists/oss-security/2017/01/20/16 it's fine to attach the reproducer, attached is the original read62.ics from Augustin Mista. Regards, Salvatore BEGIN:VCALENDAR VERSION;a=;b="a","a";c="a","b":2.1 PRODID:b CALSCALE:c b;b=;b="a";a=: BEGIN:VTIMEZONE

Bug#852034: libical: CVE-2016-9584: heap use-after-free

2017-01-20 Thread Salvatore Bonaccorso
Source: libical Version: 1.0-1.3 Severity: important Tags: security upstream Hi, the following vulnerability was published for libical. CVE-2016-9584[0]: | libical allows remote attackers to cause a denial of service | (use-after-free) and possibly read heap memory via a crafted ics file. The