CVE-2023-43789: Libxpm: out of bounds read on xpm with corrupted colormap
A vulnerability was found in libXpm where a vulnerability exists due to a boundary condition, a local user can trigger an out-of-bounds read error and read contents of memory on the system.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-43789?
CVE-2023-43789 is a vulnerability in libXpm that allows for an out-of-bounds read on XPM files with a corrupted colormap.
Which software is affected by CVE-2023-43789?
The libXpm package versions 1:3.5.12-1ubuntu0.20.04.2 (Ubuntu Focal), 1:3.5.12-1ubuntu0.22.04.2 (Ubuntu Jammy), 1:3.5.12-1.1ubuntu0.1 (Ubuntu Lunar), and 3.5.17 (Ubuntu Upstream) are affected.
How do I fix CVE-2023-43789?
To fix CVE-2023-43789, update the libXpm package to version 1:3.5.12-1ubuntu0.20.04.2 (Ubuntu Focal), 1:3.5.12-1ubuntu0.22.04.2 (Ubuntu Jammy), 1:3.5.12-1.1ubuntu0.1 (Ubuntu Lunar), or 3.5.17 (Ubuntu Upstream).
Where can I find more information about CVE-2023-43789?
You can find more information about CVE-2023-43789 on the following references: CVE Mitre (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-43789), Ubuntu Security Notices (https://ubuntu.com/security/notices/USN-6408-1), NIST NVD (https://nvd.nist.gov/vuln/detail/CVE-2023-43789).