Vulnerability Name: | CVE-2022-4883 (CCN-244934) | ||||||||||||||||
Assigned: | 2023-01-17 | ||||||||||||||||
Published: | 2023-01-17 | ||||||||||||||||
Updated: | 2023-01-17 | ||||||||||||||||
Summary: | libXpm: compression commands depend on $PATH | ||||||||||||||||
CVSS v3 Severity: | 9.8 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) 8.5 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
7.1 High (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||||||
CVSS v2 Severity: | 10.0 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||||||||||
Vulnerability Type: | CWE-426 | ||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2022-4883 Source: XF Type: UNKNOWN libxpm-cve20224883-code-exec(244934) Source: CCN Type: libXpm Web site [ANNOUNCE] libXpm 3.5.15 Source: CCN Type: OSS Mailing List, Tue, 17 Jan 2023 08:47:45 -0800 Fwd: X.Org Security Advisory: Issues handling XPM files in libXpm prior to 3.5.15 | ||||||||||||||||
Vulnerable Configuration: | Configuration RedHat 1: Denotes that component is vulnerable | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |