libXpm: compression commands depend on $PATH
Published Feb 7, 2023
8.8
HIGHCVSS 3.1
EPSS 1.20%
Description
A flaw was found in libXpm. When processing files with .Z or .gz extensions, the library calls external programs to compress and uncompress files, relying on the PATH environment variable to find these programs, which could allow a malicious user to execute other programs by manipulating the PATH environment variable.
Affected products
- Vendor n/a Product libXpm Defaultn/a
- Version 3.5.15StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | libXpm | n/a |
|
No data.
Red Hat Enterprise Linux 7
libXpm-0:3.5.12-2.el7_9
Fixed · RHSA-2023:0377
Red Hat Enterprise Linux 8
libXpm-0:3.5.12-9.el8_7
Fixed · RHSA-2023:0379
Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions
libXpm-0:3.5.12-9.el8_1
Fixed · RHSA-2023:0384
Red Hat Enterprise Linux 8.2 Advanced Update Support
libXpm-0:3.5.12-9.el8_2
Fixed · RHSA-2023:0380
Red Hat Enterprise Linux 8.2 Telecommunications Update Service
libXpm-0:3.5.12-9.el8_2
Fixed · RHSA-2023:0380
Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions
libXpm-0:3.5.12-9.el8_2
Fixed · RHSA-2023:0380
Red Hat Enterprise Linux 8.4 Extended Update Support
libXpm-0:3.5.12-9.el8_4
Fixed · RHSA-2023:0382
Red Hat Enterprise Linux 8.6 Extended Update Support
libXpm-0:3.5.12-9.el8_6
Fixed · RHSA-2023:0378
Red Hat Enterprise Linux 9
libXpm-0:3.5.13-8.el9_1
Fixed · RHSA-2023:0383
Red Hat Enterprise Linux 9.0 Extended Update Support
libXpm-0:3.5.13-8.el9_0
Fixed · RHSA-2023:0381
Red Hat Enterprise Linux 6
libXpm
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | libXpm-0:3.5.12-2.el7_9 | Fixed | RHSA-2023:0377 |
| Red Hat Enterprise Linux 8 | libXpm-0:3.5.12-9.el8_7 | Fixed | RHSA-2023:0379 |
| Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions | libXpm-0:3.5.12-9.el8_1 | Fixed | RHSA-2023:0384 |
| Red Hat Enterprise Linux 8.2 Advanced Update Support | libXpm-0:3.5.12-9.el8_2 | Fixed | RHSA-2023:0380 |
| Red Hat Enterprise Linux 8.2 Telecommunications Update Service | libXpm-0:3.5.12-9.el8_2 | Fixed | RHSA-2023:0380 |
| Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions | libXpm-0:3.5.12-9.el8_2 | Fixed | RHSA-2023:0380 |
| Red Hat Enterprise Linux 8.4 Extended Update Support | libXpm-0:3.5.12-9.el8_4 | Fixed | RHSA-2023:0382 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | libXpm-0:3.5.12-9.el8_6 | Fixed | RHSA-2023:0378 |
| Red Hat Enterprise Linux 9 | libXpm-0:3.5.13-8.el9_1 | Fixed | RHSA-2023:0383 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | libXpm-0:3.5.13-8.el9_0 | Fixed | RHSA-2023:0381 |
| Red Hat Enterprise Linux 6 | libXpm | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Enterprise Linux 6 is affected but out of support scope because libXpm is not listed in Red Hat Enterprise Linux 6 ELS Inclusion List[1]. [1]. https://access.redhat.com/articles/4997301
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (8)
- https://access.redhat.com/security/cve/CVE-2022-4883 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2160213 Issue TrackingPatchThird Party Advisory
- https://gitlab.freedesktop.org/xorg/lib/libxpm/-/commit/515294bb8023a45ff91669
- https://gitlab.freedesktop.org/xorg/lib/libxpm/-/merge_requests/9
- https://lists.debian.org/debian-lts-announce/2023/06/msg00021.html mailing-list
- https://lists.x.org/archives/xorg-announce/2023-January/003312.html
- https://nvd.nist.gov/vuln/detail/CVE-2022-4883
- https://www.cve.org/CVERecord?id=CVE-2022-4883
Change history (0)
No recorded changes yet.