Information disclosure in libXpm - CVE-2023-24040
Published: January 24, 2023
libXpm
xorg.freedesktop.org
Description
The vulnerability allows a local user to gain access to potentially sensitive information.
The vulnerability exists due to insufficient input validation within the parser of lpstat in dtprintinfo. A local user can inject arbitrary printer names via the $HOME/.printers file, manipulate the control flow and disclose memory contents on Solaris 10 systems.