Alerts This Week
Warning Icon 1 535
Alerts This Week
Warning Icon 1 535

Debian: DSA-3772-1 Critical: libXpm Integer Overflow Leading To DoS

debian
Calendar Grey January 26, 2017
Debian Logo
The recent Debian security update DSA-3772-1 addresses critical integer overflow vulnerabilities within libXpm, which could lead to possible denial of service or arbitrary code execution.
Tobias Stoeckmann discovered that the libXpm library contained two integer overflow flaws, leading to a heap out-of-bounds write, while parsing XPM extensions in a file

Summary

For the stable distribution (jessie), this problem has been fixed in
version 1:3.5.12-0+deb8u1. This update is based on a new upstream
version of libxpm including additional bug fixes.

For the testing distribution (stretch) and the unstable distribution
(sid), this problem has been fixed in version 1:3.5.12-1.

We recommend that you upgrade your libxpm packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
critical
Lowest
Low
Medium
High
Critical

Package: libxpm
CVE ID: CVE-2016-10164

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here