From ${URL} : Multiple heap over-read issues were identified in libical. Upstream bugs (not public yet): https://bugzilla.mozilla.org/show_bug.cgi?id=1280832 https://bugzilla.mozilla.org/show_bug.cgi?id=1281041 https://bugzilla.mozilla.org/show_bug.cgi?id=1281043 CVE assignment: http://seclists.org/oss-sec/2016/q2/604 @maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
There is a libical-2.0.0 since late July, should be possible to stabilize that one now.
@ Joakim: Our version in tree (dev-libs/libical-2.0.0-r1 as of today) _is_ affected.
This issue was resolved and addressed in GLSA 201904-02 at https://security.gentoo.org/glsa/201904-02 by GLSA coordinator Aaron Bauman (b-man).