ELSA-2024-2974

ELSA-2024-2974 - libXpm security update

Type:SECURITY
Severity:MODERATE
Release Date:2024-05-23

Description


[3.5.12-11]
- Drop hardening patches from previous version to keep ABI compatibility

[3.5.12-10]
- CVE-2023-43786 libX11: stack exhaustion from infinite recursion
in PutSubImage()
- CVE-2023-43787 libX11: integer overflow in XCreateImage() leading to
a heap overflow
- CVE-2023-43788 libXpm: out of bounds read in XpmCreateXpmImageFromBuffer()
- CVE-2023-43789 libXpm: out of bounds read on XPM with corrupted colormap


Related CVEs


CVE-2023-43788
CVE-2023-43789

Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By AdvisoryChannel Label
Oracle Linux 8 (aarch64) libXpm-3.5.12-11.el8.src.rpm5400892af10296747dee6394a5e229c6-ol8_aarch64_appstream
libXpm-3.5.12-11.el8.aarch64.rpm5992299968a7d6ac1c39f66b3d1f69e8-ol8_aarch64_appstream
libXpm-devel-3.5.12-11.el8.aarch64.rpm3fd4d92b3c96686019247a033ac691d9-ol8_aarch64_appstream
Oracle Linux 8 (x86_64) libXpm-3.5.12-11.el8.src.rpm5400892af10296747dee6394a5e229c6-ol8_x86_64_appstream
libXpm-3.5.12-11.el8.i686.rpm491a448b689b5ed5864fbf6cd99213b2-ol8_x86_64_appstream
libXpm-3.5.12-11.el8.x86_64.rpm870085b31cafcecd5ea7b279c28388cd-ol8_x86_64_appstream
libXpm-devel-3.5.12-11.el8.i686.rpm4e2b2d123e3ac62cfdaf3b94565c0425-ol8_x86_64_appstream
libXpm-devel-3.5.12-11.el8.x86_64.rpm60a4217e9660d82b783b435a5b14a58f-ol8_x86_64_appstream



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete