Advisories ยป MGASA-2023-0031

Updated libxpm packages fix security vulnerability

Publication date: 07 Feb 2023
Modification date: 06 Feb 2023
Type: security
Affected Mageia releases : 8
CVE: CVE-2022-4883 , CVE-2022-44617 , CVE-2022-46285

Description

libXpm incorrectly handled calling external helper binaries.  If libXpm
was being used by a setuid binary, a local attacker could possibly use
this issue to escalate privileges. (CVE-2022-4883)

libXpm incorrectly handled certain XPM files.  If a user or automated
system were tricked into opening a specially crafted XPM file, a remote
attacker could possibly use this issue to cause libXpm to stop responding,
resulting in a denial of service. (CVE-2022-44617, CVE-2022-46285)
                

References

SRPMS

8/core