Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-4367

Опубликовано: 16 июн. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 5.5

Описание

A flaw was found in libXpm. A local user with low privileges could exploit an Out-of-Bounds Read vulnerability in the xpmNextWord() function by processing a specially crafted or very small XPM (X PixMap) image file. This improper validation of file boundaries can cause an internal pointer to read beyond the file's end, leading to application crashes and Denial of Service conditions.

РелизСтатусПримечание
devel

not-affected

1:3.5.19-1
esm-infra-legacy/trusty

needs-triage

esm-infra-legacy/xenial

needs-triage

esm-infra/bionic

needs-triage

esm-infra/focal

needs-triage

esm-infra/xenial

ignored

end of ESM support, was needs-triage
jammy

released

1:3.5.12-1ubuntu0.22.04.3
noble

released

1:3.5.17-1ubuntu0.24.04.1
questing

ignored

end of life, was needed
resolute

released

1:3.5.17-1ubuntu0.26.04.1

Показывать по

РелизСтатусПримечание
devel

needs-triage

esm-apps-legacy/xenial

needs-triage

esm-apps/bionic

needs-triage

esm-apps/focal

needs-triage

esm-apps/jammy

needs-triage

esm-apps/noble

needs-triage

esm-apps/resolute

needs-triage

esm-apps/xenial

ignored

end of ESM support, was needs-triage
esm-infra-legacy/trusty

needs-triage

jammy

needs-triage

Показывать по

EPSS

Процентиль: 3%
0.00129
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
redhat
4 месяца назад

A flaw was found in libXpm. A local user with low privileges could exploit an Out-of-Bounds Read vulnerability in the `xpmNextWord()` function by processing a specially crafted or very small XPM (X PixMap) image file. This improper validation of file boundaries can cause an internal pointer to read beyond the file's end, leading to application crashes and Denial of Service conditions.

CVSS3: 5.5
nvd
около 2 месяцев назад

A flaw was found in libXpm. A local user with low privileges could exploit an Out-of-Bounds Read vulnerability in the `xpmNextWord()` function by processing a specially crafted or very small XPM (X PixMap) image file. This improper validation of file boundaries can cause an internal pointer to read beyond the file's end, leading to application crashes and Denial of Service conditions.

CVSS3: 5.5
msrc
около 1 месяца назад

Libxpm: libxpm: denial of service via out-of-bounds read in xpm file parsing

CVSS3: 5.5
debian
около 2 месяцев назад

A flaw was found in libXpm. A local user with low privileges could exp ...

suse-cvrf
около 2 месяцев назад

Security update for libXpm

EPSS

Процентиль: 3%
0.00129
Низкий

5.5 Medium

CVSS3