QID 356987
Date Published: 2024-01-17
QID 356987: Amazon Linux Security Advisory for libXpm : AL2012-2023-471
Package updates are available for Amazon Linux that fix the following vulnerabilities:
CVE-2023-43789:
libXpm: out of bounds read on XPM with corrupted colormap
CVE-2023-43787:
libX11: integer overflow in XCreateImage() leading to a heap overflow.
CVE-2023-43786:
A vulnerability was found in libX11 due to an infinite loop within the PutSubImage() function. This flaw allows a local user to consume all available system resources and cause a denial of service condition.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Administrators are advised to apply the appropriate software updates.
Vendor References
CVEs related to QID 356987
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| AL2012-2023-471 | Amazon Linux Bare Metal |
|