PT-2017-3928 · Mozilla+5 · Thunderbird+5

Brandonprry

·

Publicado

2014-12-26

·

Atualizado

2024-06-15

·

CVE-2016-5824

CVSS v2.0

7.1

Alta

VetorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions libical version 1.0 Thunderbird (affected versions not specified)
Description The issue allows remote attackers to cause a denial of service. It is related to a use-after-free error, which can be triggered by a crafted ics file. The vulnerability is also associated with a memory usage issue after release, potentially enabling a remote attacker to cause a service disruption.
Recommendations For libical version 1.0, update to a version that fixes the use-after-free error. For Thunderbird, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Use After Free

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2014-2495
ALT-PU-2019-1171
BDU:2020-00726
CESA-2019_0269
CESA-2019_0270
CVE-2016-5824
DLA-959-1
MGASA-2018-0021
OPENSUSE-SU-2019:0249-1
OPENSUSE-SU-2019:0251-1
OPENSUSE-SU-2019_0182-1
OPENSUSE-SU-2019_0251-1
OPENSUSE-SU-2024:10601-1
RHSA-2019:0269
RHSA-2019:0270
RHSA-2019_0269
RHSA-2019_0270
SUSE-SU-2017:1989-1
SUSE-SU-2017_1989-1
SUSE-SU-2018:0119-1
SUSE-SU-2019:0338-1
USN-3897-1

Produtos afetados

Alt Linux
Centos
Red Hat
Suse
Thunderbird
Ubuntu