Vulnerability Bulletins

DSA-3772 libxpm - security update

   
Affected software Debian
 
Tobias Stoeckmann discovered that the libXpm library contained twointeger overflow flaws, leading to a heap out-of-bounds write, whileparsing XPM extensions in a file. An attacker can provide a speciallycrafted XPM file that, when processed by an application using the libXpmlibrary, would cause a denial-of-service against the application, orpotentially, the execution of arbitrary code with the privileges of theuser running the application.

More info:

https://www.debian.org/security/2017/dsa-3772