CVE-2022-44617 is a Denial of Service (DoS) vulnerability in the libXpm library, affecting x.org libxpm. This flaw allows an attacker to trigger an infinite loop by providing a specially crafted file with a width of zero and a very large height, causing applications linked to the library to become unresponsive. Rated 7.5 HIGH, it has a low attack complexity and requires no user interaction or privileges, with the primary impact being availability. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.5.15CPE matchmatch criteria | cpe:2.3:a:x.org:libxpm:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
A flaw was found in libXpm. When processing a file with width of 0 and a very large height some parser functions will be called repeatedly and can lead to an infinite loop resulting in a Denial of Service in the application linked to the library.
Feb 14, 2023libXpm: Runaway loop on width of 0 and enormous height
Jan 17, 2023