Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.1.10.2023.0031
Categoría:Mageia Linux Local Security Checks
Título:Mageia: Security Advisory (MGASA-2023-0031)
Resumen:The remote host is missing an update for the 'libxpm' package(s) announced via the MGASA-2023-0031 advisory.
Descripción:Summary:
The remote host is missing an update for the 'libxpm' package(s) announced via the MGASA-2023-0031 advisory.

Vulnerability Insight:
libXpm incorrectly handled calling external helper binaries. If libXpm
was being used by a setuid binary, a local attacker could possibly use
this issue to escalate privileges. (CVE-2022-4883)

libXpm incorrectly handled certain XPM files. If a user or automated
system were tricked into opening a specially crafted XPM file, a remote
attacker could possibly use this issue to cause libXpm to stop responding,
resulting in a denial of service. (CVE-2022-44617, CVE-2022-46285)

Affected Software/OS:
'libxpm' package(s) on Mageia 8.

Solution:
Please install the updated package(s).

CVSS Score:
9.0

CVSS Vector:
AV:N/AC:L/Au:S/C:C/I:C/A:C

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2022-44617
https://gitlab.freedesktop.org/xorg/lib/libxpm/-/commit/f80fa6ae47ad4a5beacb28
https://gitlab.freedesktop.org/xorg/lib/libxpm/-/merge_requests/9
https://lists.x.org/archives/xorg-announce/2023-January/003312.html
https://bugzilla.redhat.com/show_bug.cgi?id=2160193
https://lists.debian.org/debian-lts-announce/2023/06/msg00021.html
Common Vulnerability Exposure (CVE) ID: CVE-2022-46285
https://gitlab.freedesktop.org/xorg/lib/libxpm/-/commit/a3a7c6dcc3b629d7650148
https://bugzilla.redhat.com/show_bug.cgi?id=2160092
http://www.openwall.com/lists/oss-security/2023/10/03/1
http://www.openwall.com/lists/oss-security/2023/10/03/10
Common Vulnerability Exposure (CVE) ID: CVE-2022-4883
https://gitlab.freedesktop.org/xorg/lib/libxpm/-/commit/515294bb8023a45ff91669
https://bugzilla.redhat.com/show_bug.cgi?id=2160213
CopyrightCopyright (C) 2023 Greenbone AG

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.