All errata/sisyphus/ALT-PU-2026-6607-2
ALT-PU-2026-6607-2

Package update libXpm in branch sisyphus

Version3.5.19-alt1
Published2026-08-29
Max severityMEDIUM
Severity:

Closed issues (2)

BDU:2026-12811
MEDIUM6.3

Уязвимость библиотеки для работы с файлами изображений X Pixmap (XPM) LibXpm, связанная с чтением за допустимыми границами буфера данных, позволяющая нарушителю вызвать отказ в обслуживании

Published: 2026-08-27
CVSS 3.xMEDIUM 6.3
CVSS:3.x/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H
CVSS 2.0MEDIUM 5.6
CVSS:2.0/AV:L/AC:H/Au:N/C:C/I:N/A:C
CVE-2026-4367
MEDIUM5.5

A flaw was found in libXpm. A local user with low privileges could exploit an Out-of-Bounds Read vulnerability in the `xpmNextWord()` function by processing a specially crafted or very small XPM (X PixMap) image file. This improper validation of file boundaries can cause an internal pointer to read beyond the file's end, leading to application crashes and Denial of Service conditions.

Published: 2026-06-16Modified: 2026-07-28
CVSS 3.xMEDIUM 5.5
CVSS:3.x/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H