Thunderbird libical Heap Overflow

Discussion in 'News Aggregator' started by Packet Storm, 15 Jun 2019.

  1. Packet Storm

    Packet Storm Guest

    A heap-based buffer overflow has been identified in the Thunderbird email client. The issue is present in the libical implementation, which was forked from upstream libical version 0.47. The issue can be triggered remotely, when an attacker sends an specially crafted calendar attachment and does not require user interaction. It might be used by a remote attacker to crash or gain remote code execution in the client system. Proof of concept included.

    Continue reading...
     

Share This Page

Loading...