CVE-2022-46285 is a Denial of Service vulnerability in libXpm, affecting x.org libxpm, where an unclosed comment in a parsed file can lead to an infinite loop. This high-severity flaw (CVSS 7.5) is easily exploitable over the network without user interaction, causing application unavailability. While there is no known active exploitation or public exploit code, the vulnerability has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.5.15CPE matchmatch criteria | cpe:2.3:a:x.org:libxpm:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
A flaw was found in libXpm. This issue occurs when parsing a file with a comment not closed; the end-of-file condition will not be detected leading to an infinite loop and resulting in a Denial of Service in the application linked to the library.
Feb 14, 2023libXpm: Infinite loop on unclosed comments
Jan 17, 2023