Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-4367

Опубликовано: 16 июн. 2026
Источник: debian

Описание

A flaw was found in libXpm. A local user with low privileges could exploit an Out-of-Bounds Read vulnerability in the `xpmNextWord()` function by processing a specially crafted or very small XPM (X PixMap) image file. This improper validation of file boundaries can cause an internal pointer to read beyond the file's end, leading to application crashes and Denial of Service conditions.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libxpmfixed1:3.5.19-1package
libxpmfixed1:3.5.17-1+deb13u1trixiepackage
libxpmno-dsabookwormpackage
libxpmpostponedbullseyepackage

Примечания

  • https://www.openwall.com/lists/oss-security/2026/04/21/3

  • https://gitlab.freedesktop.org/xorg/lib/libxpm/-/commit/5448e1bd7252780b16db869c2253d24e0fe0ae18 (libXpm-3.5.19)

  • https://gitlab.freedesktop.org/xorg/lib/libxpm/-/merge_requests/31

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 2 месяцев назад

A flaw was found in libXpm. A local user with low privileges could exploit an Out-of-Bounds Read vulnerability in the `xpmNextWord()` function by processing a specially crafted or very small XPM (X PixMap) image file. This improper validation of file boundaries can cause an internal pointer to read beyond the file's end, leading to application crashes and Denial of Service conditions.

CVSS3: 5.5
redhat
4 месяца назад

A flaw was found in libXpm. A local user with low privileges could exploit an Out-of-Bounds Read vulnerability in the `xpmNextWord()` function by processing a specially crafted or very small XPM (X PixMap) image file. This improper validation of file boundaries can cause an internal pointer to read beyond the file's end, leading to application crashes and Denial of Service conditions.

CVSS3: 5.5
nvd
около 2 месяцев назад

A flaw was found in libXpm. A local user with low privileges could exploit an Out-of-Bounds Read vulnerability in the `xpmNextWord()` function by processing a specially crafted or very small XPM (X PixMap) image file. This improper validation of file boundaries can cause an internal pointer to read beyond the file's end, leading to application crashes and Denial of Service conditions.

CVSS3: 5.5
msrc
около 1 месяца назад

Libxpm: libxpm: denial of service via out-of-bounds read in xpm file parsing

suse-cvrf
около 2 месяцев назад

Security update for libXpm