Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-13248.json
JSON Data
https://api.test.osv.dev/v1/vulns/AZL-13248
Upstream
Published
2023-02-07T19:15:09Z
Modified
2026-04-01T05:07:36.642640Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
CVE-2022-4883 affecting package libXpm for versions less than 3.5.17-1
Details

A flaw was found in libXpm. When processing files with .Z or .gz extensions, the library calls external programs to compress and uncompress files, relying on the PATH environment variable to find these programs, which could allow a malicious user to execute other programs by manipulating the PATH environment variable.

References

Affected packages

Azure Linux:2 / libXpm

Package

Name
libXpm
Purl
pkg:rpm/azure-linux/libXpm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.5.17-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-13248.json"