Out-of-bounds read in libXpm - CVE-2023-43789
Published: October 3, 2023
Vulnerability identifier: #VU81436
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-43789
CWE-ID: CWE-125
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition. A local user can trigger an out-of-bounds read error and read contents of memory on the system.
Affected software
libXpm
Cloud Pak for Network Automation
Enterprise SONiC
IBM Cloud Pak for Watson AIOps
Gentoo Linux
Debian Linux
Amazon Linux AMI
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Workstation Extension 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Software Development Kit 12
SUSE Manager Server
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Linux Enterprise Micro
OpenBSD
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Anolis OS
Slackware Linux
Ubuntu
SUSE Package Hub 15
Basesystem Module
openSUSE Leap
openEuler
Fedora
Data Lakehouse
Isolation Segment
VMware Tanzu Application Service for VMs
IBM Qradar SIEM
Juniper Secure Analytics (JSA)
libxpm4 (Ubuntu package)
motif-static
motif-devel
motif
motif (Red Hat package)
libXpm
libXpm-tools-debuginfo
libXpm4-debuginfo-32bit
libXpm-tools
libXpm-devel
libXpm-debugsource
libXpm4-32bit
libXpm4
libXpm4-debuginfo
libxpm (Debian package)
libXpm (Red Hat package)
libXpm-devel-32bit
libXpm4-32bit-debuginfo
libXpm-help
libXpm-debuginfo
libXpm-doc
x11-libs/libXpm
OpenShift API for Data Protection (OADP)
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
VMware Tanzu Operations Manager
RecoverPoint for VMs
Cloud Pak for Network Automation
Enterprise SONiC
IBM Cloud Pak for Watson AIOps
Gentoo Linux
Debian Linux
Amazon Linux AMI
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Workstation Extension 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Software Development Kit 12
SUSE Manager Server
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Linux Enterprise Micro
OpenBSD
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Anolis OS
Slackware Linux
Ubuntu
SUSE Package Hub 15
Basesystem Module
openSUSE Leap
openEuler
Fedora
Data Lakehouse
Isolation Segment
VMware Tanzu Application Service for VMs
IBM Qradar SIEM
Juniper Secure Analytics (JSA)
libxpm4 (Ubuntu package)
motif-static
motif-devel
motif
motif (Red Hat package)
libXpm
libXpm-tools-debuginfo
libXpm4-debuginfo-32bit
libXpm-tools
libXpm-devel
libXpm-debugsource
libXpm4-32bit
libXpm4
libXpm4-debuginfo
libxpm (Debian package)
libXpm (Red Hat package)
libXpm-devel-32bit
libXpm4-32bit-debuginfo
libXpm-help
libXpm-debuginfo
libXpm-doc
x11-libs/libXpm
OpenShift API for Data Protection (OADP)
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
VMware Tanzu Operations Manager
RecoverPoint for VMs
How to mitigate CVE-2023-43789
Install updates from vendor's website.
libXpm - update to 3.5.17
Data Lakehouse - update to 1.1.0.0
Cloud Pak for Network Automation - update to 2.7.4
IBM Qradar SIEM - update to 7.5.0 Update Pack 9 IF02
Juniper Secure Analytics (JSA) - update to 7.5.0 UP9 IF02
libxpm4 (Ubuntu package) - addressed in versions Ubuntu Pro, 1:3.5.12-1ubuntu0.20.04.2, 1:3.5.12-1ubuntu0.22.04.2, 1:3.5.12-1.1ubuntu0.1
OpenShift API for Data Protection (OADP) - update to 1.3.2
Migration Toolkit for Containers - update to 1.8.4
motif-static - update to 2.3.4-20
motif-devel - update to 2.3.4-20
motif - update to 2.3.4-20
motif (Red Hat package) - addressed in versions 2.3.4-20.el8, 2.3.4-28.el9
motif - addressed in versions 2.3.4-30.fc37, 2.3.4-30.fc38, 2.3.4-30.fc39
VMware Tanzu Operations Manager - addressed in versions 2.7.25, 2.8.16, 2.9.12, 2.10.39
Isolation Segment - addressed in versions 2.11.42, 2.13.27, 3.0.18, 3.0.20, 4.0.10, 4.0.12
VMware Tanzu Application Service for VMs - addressed in versions 2.11.48, 2.13.30, 3.0.18, 3.0.20, 4.0.10, 4.0.12
libXpm - addressed in versions 3.5.10-2.12, 3.5.15-2
libXpm-tools-debuginfo - addressed in versions 3.5.11-6.10.1, 3.5.12-150000.3.10.1
libXpm4-debuginfo-32bit - update to 3.5.11-6.10.1
libXpm-tools - addressed in versions 3.5.11-6.10.1, 3.5.12-150000.3.10.1
libXpm-devel - addressed in versions 3.5.11-6.10.1, 3.5.12-150000.3.10.1
libXpm-debugsource - addressed in versions 3.5.11-6.10.1, 3.5.12-150000.3.10.1
libXpm4-32bit - addressed in versions 3.5.11-6.10.1, 3.5.12-150000.3.10.1
libXpm4 - addressed in versions 3.5.11-6.10.1, 3.5.12-150000.3.10.1
libXpm4-debuginfo - addressed in versions 3.5.11-6.10.1, 3.5.12-150000.3.10.1
libxpm (Debian package) - addressed in versions 1:3.5.12-1.1+deb11u1, 1:3.5.12-1.1+deb12u1
libXpm (Red Hat package) - addressed in versions 3.5.12-11.el8, 3.5.13-10.el9
libXpm-devel-32bit - update to 3.5.12-150000.3.10.1
libXpm4-32bit-debuginfo - update to 3.5.12-150000.3.10.1
libXpm-devel - update to 3.5.13-3
libXpm-help - update to 3.5.13-3
libXpm-debugsource - update to 3.5.13-3
libXpm - update to 3.5.13-3
libXpm-debuginfo - update to 3.5.13-3
libXpm - addressed in versions 3.5.13-10.0.1, 3.5.17-1
libXpm-devel - addressed in versions 3.5.13-10.0.1, 3.5.17-1
libXpm-doc - addressed in versions 3.5.13-10.0.1, 3.5.17-1
libXpm - update to 3.5.17
x11-libs/libXpm - update to 3.5.17
libXpm - update to 3.5.17-1.fc39
Enterprise SONiC - update to 4.2.1
IBM Cloud Pak for Watson AIOps - update to 4.6.0
Red Hat OpenShift Container Platform - addressed in versions 4.13.45, 4.14.32, 4.14.33, 4.16.15, 4.17.0
RecoverPoint for VMs - update to 6.0.SP1.P1
Data Lakehouse - update to 1.1.0.0
Cloud Pak for Network Automation - update to 2.7.4
IBM Qradar SIEM - update to 7.5.0 Update Pack 9 IF02
Juniper Secure Analytics (JSA) - update to 7.5.0 UP9 IF02
libxpm4 (Ubuntu package) - addressed in versions Ubuntu Pro, 1:3.5.12-1ubuntu0.20.04.2, 1:3.5.12-1ubuntu0.22.04.2, 1:3.5.12-1.1ubuntu0.1
OpenShift API for Data Protection (OADP) - update to 1.3.2
Migration Toolkit for Containers - update to 1.8.4
motif-static - update to 2.3.4-20
motif-devel - update to 2.3.4-20
motif - update to 2.3.4-20
motif (Red Hat package) - addressed in versions 2.3.4-20.el8, 2.3.4-28.el9
motif - addressed in versions 2.3.4-30.fc37, 2.3.4-30.fc38, 2.3.4-30.fc39
VMware Tanzu Operations Manager - addressed in versions 2.7.25, 2.8.16, 2.9.12, 2.10.39
Isolation Segment - addressed in versions 2.11.42, 2.13.27, 3.0.18, 3.0.20, 4.0.10, 4.0.12
VMware Tanzu Application Service for VMs - addressed in versions 2.11.48, 2.13.30, 3.0.18, 3.0.20, 4.0.10, 4.0.12
libXpm - addressed in versions 3.5.10-2.12, 3.5.15-2
libXpm-tools-debuginfo - addressed in versions 3.5.11-6.10.1, 3.5.12-150000.3.10.1
libXpm4-debuginfo-32bit - update to 3.5.11-6.10.1
libXpm-tools - addressed in versions 3.5.11-6.10.1, 3.5.12-150000.3.10.1
libXpm-devel - addressed in versions 3.5.11-6.10.1, 3.5.12-150000.3.10.1
libXpm-debugsource - addressed in versions 3.5.11-6.10.1, 3.5.12-150000.3.10.1
libXpm4-32bit - addressed in versions 3.5.11-6.10.1, 3.5.12-150000.3.10.1
libXpm4 - addressed in versions 3.5.11-6.10.1, 3.5.12-150000.3.10.1
libXpm4-debuginfo - addressed in versions 3.5.11-6.10.1, 3.5.12-150000.3.10.1
libxpm (Debian package) - addressed in versions 1:3.5.12-1.1+deb11u1, 1:3.5.12-1.1+deb12u1
libXpm (Red Hat package) - addressed in versions 3.5.12-11.el8, 3.5.13-10.el9
libXpm-devel-32bit - update to 3.5.12-150000.3.10.1
libXpm4-32bit-debuginfo - update to 3.5.12-150000.3.10.1
libXpm-devel - update to 3.5.13-3
libXpm-help - update to 3.5.13-3
libXpm-debugsource - update to 3.5.13-3
libXpm - update to 3.5.13-3
libXpm-debuginfo - update to 3.5.13-3
libXpm - addressed in versions 3.5.13-10.0.1, 3.5.17-1
libXpm-devel - addressed in versions 3.5.13-10.0.1, 3.5.17-1
libXpm-doc - addressed in versions 3.5.13-10.0.1, 3.5.17-1
libXpm - update to 3.5.17
x11-libs/libXpm - update to 3.5.17
libXpm - update to 3.5.17-1.fc39
Enterprise SONiC - update to 4.2.1
IBM Cloud Pak for Watson AIOps - update to 4.6.0
Red Hat OpenShift Container Platform - addressed in versions 4.13.45, 4.14.32, 4.14.33, 4.16.15, 4.17.0
RecoverPoint for VMs - update to 6.0.SP1.P1
External References
Related Security Bulletins
- Multiple vulnerabilities in libXpm
- Ubuntu update for libxpm
- Slackware Linux update for libXpm
- SUSE update for libXpm
- SUSE update for libXpm
- OpenBSD update for libX11 and libXpm
- Fedora 39 update for libXpm
- Debian update for libxpm
- VMware Tanzu products update for libXpm
- Ubuntu update for libxpm
- Amazon Linux AMI update for libXpm
- Fedora 39 update for motif
- Fedora 38 update for motif
- Fedora 37 update for motif
- VMware Tanzu products update for libXpm
- openEuler update for libXpm
- Red Hat Enterprise Linux 9 update for libXpm
- Red Hat Enterprise Linux 9 update for motif
- Red Hat Enterprise Linux 8 update for libXpm
- Red Hat Enterprise Linux 8 update for motif
- Multiple vulnerabilities in Dell Enterprise SONiC Distribution
- Multiple vulnerabilities in OpenShift API for Data Protection (OADP) 1.3
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in IBM Cloud Pak for AIOps
- Multiple vulnerabilities in Dell Data Lakehouse System Software
- Multiple vulnerabilities in IBM Cloud Pak for Network Automation
- Gentoo update for libXpm
- Multiple vulnerabilities in IBM Qradar SIEM
- Multiple vulnerabilities in Juniper Secure Analytics (JSA)
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in Migration Toolkit for Containers 1.8
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Multiple vulnerabilities in Dell RecoverPoint for Virtual Machines
- Amazon Linux AMI update for libXpm
- Anolis OS update for libXpm
- Anolis OS update for libXpm
- Anolis OS update for motif