HIGH 8.8 Microsoft
CVE-2022-4883
A flaw was found in libXpm. When processing files with .Z or .gz extensions the library calls external programs to compress and uncompress files relying on the PATH environment variable to find these programs which could allow a malicious user to execute other programs by manipulating the PATH environment variable.
Microsoft Security Update 2023-Feb: A flaw was found in libXpm. When processing files with .Z or .gz extensions the library calls external programs to compress and uncompress files relying on the PATH environment variable to find these programs which could allow a malicious user to execute other programs by manipulating the PATH environment variable.
Affected Products
- cbl2 libXpm 3.5.17-1 on CBL Mariner 2.0
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-4883
- https://nvd.nist.gov/vuln/detail/CVE-2022-4883
This high severity vulnerability with a CVSS score of 8.8 was published on 2023-02-14 via Microsoft. Affected: cbl2 libXpm 3.5.17-1 on CBL Mariner 2.0.
vulnfeed aggregates 11644 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.