Vulnerability in libXpm leading to code execution.

A corrective release of the libXpm library 3.5.15 has been published, developed by the X.Org project and used for processing files in the XPM format. In the new version, three vulnerabilities have been addressed, two of which (CVE-2022-46285, CVE-2022-44617) lead to infinite looping when processing specially crafted XPM files. The third vulnerability (CVE-2022-4883) allows arbitrary commands to be executed when applications using libXpm run. When launching privileged processes related to libXpm, such as programs with the suid root flag, the vulnerability allows for privilege escalation.

The vulnerability is caused by the way libXpm handles compressed XPM files — when processing XPM.Z or XPM.gz files, the library uses execlp() to start external unpacking utilities (uncompress or gunzip), the path to which is calculated based on the PATH environment variable. The attack involves placing custom executable files for uncompress or gunzip in a user-accessible directory that is present in the PATH list, which will be executed when running an application using libXpm.

The vulnerability has been fixed by replacing the execlp call with execl using absolute paths to the utilities. Additionally, a build option ‘--disable-open-zfile’ has been added, allowing the disabling of processing for compressed files and calls to external utilities for unpacking.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster