Back

CRITICAL

libical: Heap buffer over read in icalparser.c parser_get_next_char

Published Jul 23, 2019

Description

A flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in parser_get_next_char when processing certain email messages, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7.1.

Affected products

Remediation

Red Hat mitigation

Thunderbird can be configured to use icaljs instead of libical by setting `calendar.icaljs = true` in preferences, mitigating this vulnerability.

References (9)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner mozilla
Published Jul 23, 2019
Updated Aug 4, 2024
Reserved May 3, 2019

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Moderate
Public date Jun 13, 2019
Bugzilla 1720001

ENISA EUVD

Assigner mozilla
Published Jul 23, 2019
Updated Aug 4, 2024

GitHub

No data