#VU71234 Infinite loop in libXpm - CVE-2022-46285
Published: January 17, 2023 / Updated: January 20, 2023
libXpm
xorg.freedesktop.org
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to infinite loop when handling unclosed comments in XPM images within the ParseComment() function. A remote attacker can trick the victim to open a specially crafted image and cause denial of service conditions.