A flaw was found in libXpm. A local user with low privileges could exploit an Out-of-Bounds Read vulnerability in the `xpmNextWord()` function by processing a specially crafted or very small XPM (X PixMap) image file. This improper validation of file boundaries can cause an internal pointer to read beyond the file's end, leading to application crashes and Denial of Service conditions.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | All Versions ImpactedCNA affecteddefault affected | |
| Red Hat | Red Hat Enterprise Linux 6 | All Versions ImpactedCNA affecteddefault affected | |
| Red Hat | Red Hat Enterprise Linux 7 | All Versions ImpactedCNA affecteddefault affected | |
| Red Hat | Red Hat Enterprise Linux 8 | All Versions ImpactedCNA affecteddefault affected | |
| Red Hat | Red Hat Enterprise Linux 9 | All Versions ImpactedCNA affecteddefault affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.