Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-44617

Опубликовано: 06 фев. 2023
Источник: debian
EPSS Низкий

Описание

A flaw was found in libXpm. When processing a file with width of 0 and a very large height, some parser functions will be called repeatedly and can lead to an infinite loop, resulting in a Denial of Service in the application linked to the library.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libxpmfixed1:3.5.12-1.1package
libxpmfixed1:3.5.12-1.1~deb11u1bullseyepackage

Примечания

  • https://www.openwall.com/lists/oss-security/2023/01/17/2

  • https://gitlab.freedesktop.org/xorg/lib/libxpm/-/commit/f80fa6ae47ad4a5beacb287c0030c9913b046643 (libXpm-3.5.15)

  • https://gitlab.freedesktop.org/xorg/lib/libxpm/-/commit/c5ab17bcc34914c0b0707d2135dbebe9a367c5f0 (libXpm-3.5.15)

EPSS

Процентиль: 9%
0.00035
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 2 лет назад

A flaw was found in libXpm. When processing a file with width of 0 and a very large height, some parser functions will be called repeatedly and can lead to an infinite loop, resulting in a Denial of Service in the application linked to the library.

CVSS3: 7.5
redhat
больше 2 лет назад

A flaw was found in libXpm. When processing a file with width of 0 and a very large height, some parser functions will be called repeatedly and can lead to an infinite loop, resulting in a Denial of Service in the application linked to the library.

CVSS3: 7.5
nvd
больше 2 лет назад

A flaw was found in libXpm. When processing a file with width of 0 and a very large height, some parser functions will be called repeatedly and can lead to an infinite loop, resulting in a Denial of Service in the application linked to the library.

CVSS3: 7.5
github
больше 2 лет назад

A flaw was found in libXpm. When processing a file with width of 0 and a very large height, some parser functions will be called repeatedly and can lead to an infinite loop, resulting in a Denial of Service in the application linked to the library.

CVSS3: 7.5
fstec
больше 2 лет назад

Уязвимость функции ParsePixels () библиотеки для работы с файлами изображений X Pixmap (XPM) libXpm, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 9%
0.00035
Низкий