Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.1.10.2023.0031
Kategorie:Mageia Linux Local Security Checks
Titel:Mageia: Security Advisory (MGASA-2023-0031)
Zusammenfassung:The remote host is missing an update for the 'libxpm' package(s) announced via the MGASA-2023-0031 advisory.
Beschreibung:Summary:
The remote host is missing an update for the 'libxpm' package(s) announced via the MGASA-2023-0031 advisory.

Vulnerability Insight:
libXpm incorrectly handled calling external helper binaries. If libXpm
was being used by a setuid binary, a local attacker could possibly use
this issue to escalate privileges. (CVE-2022-4883)

libXpm incorrectly handled certain XPM files. If a user or automated
system were tricked into opening a specially crafted XPM file, a remote
attacker could possibly use this issue to cause libXpm to stop responding,
resulting in a denial of service. (CVE-2022-44617, CVE-2022-46285)

Affected Software/OS:
'libxpm' package(s) on Mageia 8.

Solution:
Please install the updated package(s).

CVSS Score:
9.0

CVSS Vector:
AV:N/AC:L/Au:S/C:C/I:C/A:C

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2022-44617
https://gitlab.freedesktop.org/xorg/lib/libxpm/-/commit/f80fa6ae47ad4a5beacb28
https://gitlab.freedesktop.org/xorg/lib/libxpm/-/merge_requests/9
https://lists.x.org/archives/xorg-announce/2023-January/003312.html
https://bugzilla.redhat.com/show_bug.cgi?id=2160193
https://lists.debian.org/debian-lts-announce/2023/06/msg00021.html
Common Vulnerability Exposure (CVE) ID: CVE-2022-46285
https://gitlab.freedesktop.org/xorg/lib/libxpm/-/commit/a3a7c6dcc3b629d7650148
https://bugzilla.redhat.com/show_bug.cgi?id=2160092
http://www.openwall.com/lists/oss-security/2023/10/03/1
http://www.openwall.com/lists/oss-security/2023/10/03/10
Common Vulnerability Exposure (CVE) ID: CVE-2022-4883
https://gitlab.freedesktop.org/xorg/lib/libxpm/-/commit/515294bb8023a45ff91669
https://bugzilla.redhat.com/show_bug.cgi?id=2160213
CopyrightCopyright (C) 2023 Greenbone AG

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.