Out-of-bounds read in libXpm - CVE-2023-43788

 

Out-of-bounds read in libXpm - CVE-2023-43788

Published: October 3, 2023


Vulnerability identifier: #VU81435
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-43788
CWE-ID: CWE-125
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to potentially sensitive information.

The vulnerability exists due to a boundary condition within the XpmCreateXpmImageFromBuffer() function. A local user can trigger an out-of-bounds read error and read contents of memory on the system.


Affected software

libXpm
Cloud Pak for Network Automation
Enterprise SONiC
IBM Cloud Pak for Watson AIOps
Debian Linux
Gentoo Linux
Amazon Linux AMI
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Workstation Extension 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Software Development Kit 12
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
OpenBSD
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Slackware Linux
Ubuntu
Basesystem Module
SUSE Package Hub 15
openSUSE Leap
openEuler
Fedora
Data Lakehouse
Isolation Segment
VMware Tanzu Application Service for VMs
IBM Qradar SIEM
Juniper Secure Analytics (JSA)
libxpm4 (Ubuntu package)
motif-static
motif
motif-devel
motif (Red Hat package)
libXpm
libXpm4-debuginfo
libXpm4-debuginfo-32bit
libXpm-tools-debuginfo
libXpm-tools
libXpm-devel
libXpm-debugsource
libXpm4-32bit
libXpm4
libxpm (Debian package)
libXpm (Red Hat package)
libXpm-devel-32bit
libXpm4-32bit-debuginfo
libXpm-debuginfo
libXpm-help
libXpm-doc
x11-libs/libXpm
OpenShift API for Data Protection (OADP)
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
VMware Tanzu Operations Manager
RecoverPoint for VMs

How to mitigate CVE-2023-43788

Install updates from vendor's website.

libXpm - update to 3.5.17
Data Lakehouse - update to 1.1.0.0
Cloud Pak for Network Automation - update to 2.7.4
IBM Qradar SIEM - update to 7.5.0 Update Pack 9 IF02
Juniper Secure Analytics (JSA) - update to 7.5.0 UP9 IF02
libxpm4 (Ubuntu package) - addressed in versions Ubuntu Pro, 1:3.5.12-1ubuntu0.20.04.2, 1:3.5.12-1ubuntu0.22.04.2, 1:3.5.12-1.1ubuntu0.1
OpenShift API for Data Protection (OADP) - update to 1.3.2
Migration Toolkit for Containers - update to 1.8.4
motif-static - update to 2.3.4-20
motif - update to 2.3.4-20
motif-devel - update to 2.3.4-20
motif (Red Hat package) - addressed in versions 2.3.4-20.el8, 2.3.4-28.el9
motif - addressed in versions 2.3.4-30.fc37, 2.3.4-30.fc38, 2.3.4-30.fc39
VMware Tanzu Operations Manager - addressed in versions 2.7.25, 2.8.16, 2.9.12, 2.10.39
Isolation Segment - addressed in versions 2.11.42, 2.13.27, 3.0.18, 3.0.20, 4.0.10, 4.0.12
VMware Tanzu Application Service for VMs - addressed in versions 2.11.48, 2.13.30, 3.0.18, 3.0.20, 4.0.10, 4.0.12
libXpm - addressed in versions 3.5.10-2.13, 3.5.15-2
libXpm4-debuginfo - addressed in versions 3.5.11-6.10.1, 3.5.12-150000.3.10.1
libXpm4-debuginfo-32bit - update to 3.5.11-6.10.1
libXpm-tools-debuginfo - addressed in versions 3.5.11-6.10.1, 3.5.12-150000.3.10.1
libXpm-tools - addressed in versions 3.5.11-6.10.1, 3.5.12-150000.3.10.1
libXpm-devel - addressed in versions 3.5.11-6.10.1, 3.5.12-150000.3.10.1
libXpm-debugsource - addressed in versions 3.5.11-6.10.1, 3.5.12-150000.3.10.1
libXpm4-32bit - addressed in versions 3.5.11-6.10.1, 3.5.12-150000.3.10.1
libXpm4 - addressed in versions 3.5.11-6.10.1, 3.5.12-150000.3.10.1
libxpm (Debian package) - addressed in versions 1:3.5.12-1.1+deb11u1, 1:3.5.12-1.1+deb12u1
libXpm (Red Hat package) - addressed in versions 3.5.12-11.el8, 3.5.13-10.el9
libXpm-devel-32bit - update to 3.5.12-150000.3.10.1
libXpm4-32bit-debuginfo - update to 3.5.12-150000.3.10.1
libXpm-debuginfo - update to 3.5.13-3
libXpm-devel - update to 3.5.13-3
libXpm-help - update to 3.5.13-3
libXpm - update to 3.5.13-3
libXpm-debugsource - update to 3.5.13-3
libXpm-doc - addressed in versions 3.5.13-10.0.1, 3.5.17-1
libXpm-devel - addressed in versions 3.5.13-10.0.1, 3.5.17-1
libXpm - addressed in versions 3.5.13-10.0.1, 3.5.17-1
libXpm - update to 3.5.17
x11-libs/libXpm - update to 3.5.17
libXpm - addressed in versions 3.5.17-1.fc38, 3.5.17-1.fc39
Enterprise SONiC - update to 4.2.1
IBM Cloud Pak for Watson AIOps - update to 4.6.0
Red Hat OpenShift Container Platform - addressed in versions 4.13.45, 4.14.32, 4.14.33, 4.16.15, 4.17.0
RecoverPoint for VMs - update to 6.0.SP1.P1

External References

Related Security Bulletins