A flaw was found in libXpm. When processing files with .Z or .gz extensions, the library calls external programs to compress and uncompress files, relying on the PATH environment variable to find these programs, which could allow a malicious user to execute other programs by manipulating the PATH environment variable.
{
"binaries": [
{
"binary_name": "libmotif-common",
"binary_version": "2.3.4-5ubuntu0.1"
},
{
"binary_name": "libmotif-dev",
"binary_version": "2.3.4-5ubuntu0.1"
},
{
"binary_name": "libmotif3",
"binary_version": "2.3.4-5ubuntu0.1"
},
{
"binary_name": "libmotif4",
"binary_version": "2.3.4-5ubuntu0.1"
},
{
"binary_name": "libmrm4",
"binary_version": "2.3.4-5ubuntu0.1"
},
{
"binary_name": "libuil4",
"binary_version": "2.3.4-5ubuntu0.1"
},
{
"binary_name": "libxm4",
"binary_version": "2.3.4-5ubuntu0.1"
},
{
"binary_name": "motif-clients",
"binary_version": "2.3.4-5ubuntu0.1"
},
{
"binary_name": "mwm",
"binary_version": "2.3.4-5ubuntu0.1"
},
{
"binary_name": "uil",
"binary_version": "2.3.4-5ubuntu0.1"
}
]
}{
"binaries": [
{
"binary_name": "libmotif-common",
"binary_version": "2.3.4-10"
},
{
"binary_name": "libmotif-dev",
"binary_version": "2.3.4-10"
},
{
"binary_name": "libmrm4",
"binary_version": "2.3.4-10"
},
{
"binary_name": "libuil4",
"binary_version": "2.3.4-10"
},
{
"binary_name": "libxm4",
"binary_version": "2.3.4-10"
},
{
"binary_name": "mwm",
"binary_version": "2.3.4-10"
},
{
"binary_name": "uil",
"binary_version": "2.3.4-10"
}
]
}{
"binaries": [
{
"binary_name": "libxpm-dev",
"binary_version": "1:3.5.12-1ubuntu0.18.04.2"
},
{
"binary_name": "libxpm4",
"binary_version": "1:3.5.12-1ubuntu0.18.04.2"
},
{
"binary_name": "xpmutils",
"binary_version": "1:3.5.12-1ubuntu0.18.04.2"
}
],
"availability": "No subscription required"
}{
"binaries": [
{
"binary_name": "libmotif-common",
"binary_version": "2.3.8-2build1"
},
{
"binary_name": "libmotif-dev",
"binary_version": "2.3.8-2build1"
},
{
"binary_name": "libmrm4",
"binary_version": "2.3.8-2build1"
},
{
"binary_name": "libuil4",
"binary_version": "2.3.8-2build1"
},
{
"binary_name": "libxm4",
"binary_version": "2.3.8-2build1"
},
{
"binary_name": "mwm",
"binary_version": "2.3.8-2build1"
},
{
"binary_name": "uil",
"binary_version": "2.3.8-2build1"
}
]
}{
"binaries": [
{
"binary_name": "libxpm-dev",
"binary_version": "1:3.5.12-1ubuntu0.20.04.1"
},
{
"binary_name": "libxpm4",
"binary_version": "1:3.5.12-1ubuntu0.20.04.1"
},
{
"binary_name": "xpmutils",
"binary_version": "1:3.5.12-1ubuntu0.20.04.1"
}
],
"availability": "No subscription required"
}{
"binaries": [
{
"binary_name": "libmotif-common",
"binary_version": "2.3.8-2build1"
},
{
"binary_name": "libmotif-dev",
"binary_version": "2.3.8-2build1"
},
{
"binary_name": "libmrm4",
"binary_version": "2.3.8-2build1"
},
{
"binary_name": "libuil4",
"binary_version": "2.3.8-2build1"
},
{
"binary_name": "libxm4",
"binary_version": "2.3.8-2build1"
},
{
"binary_name": "mwm",
"binary_version": "2.3.8-2build1"
},
{
"binary_name": "uil",
"binary_version": "2.3.8-2build1"
}
]
}{
"binaries": [
{
"binary_name": "libxpm-dev",
"binary_version": "1:3.5.12-1ubuntu0.22.04.1"
},
{
"binary_name": "libxpm4",
"binary_version": "1:3.5.12-1ubuntu0.22.04.1"
},
{
"binary_name": "xpmutils",
"binary_version": "1:3.5.12-1ubuntu0.22.04.1"
}
],
"availability": "No subscription required"
}{
"binaries": [
{
"binary_name": "libmotif-common",
"binary_version": "2.3.8-3"
},
{
"binary_name": "libmotif-dev",
"binary_version": "2.3.8-3"
},
{
"binary_name": "libmrm4",
"binary_version": "2.3.8-3"
},
{
"binary_name": "libuil4",
"binary_version": "2.3.8-3"
},
{
"binary_name": "libxm4",
"binary_version": "2.3.8-3"
},
{
"binary_name": "mwm",
"binary_version": "2.3.8-3"
},
{
"binary_name": "uil",
"binary_version": "2.3.8-3"
}
]
}{
"binaries": [
{
"binary_name": "libmotif-common",
"binary_version": "2.3.8-3.1build1"
},
{
"binary_name": "libmotif-dev",
"binary_version": "2.3.8-3.1build1"
},
{
"binary_name": "libmrm4",
"binary_version": "2.3.8-3.1build1"
},
{
"binary_name": "libuil4",
"binary_version": "2.3.8-3.1build1"
},
{
"binary_name": "libxm4",
"binary_version": "2.3.8-3.1build1"
},
{
"binary_name": "mwm",
"binary_version": "2.3.8-3.1build1"
},
{
"binary_name": "uil",
"binary_version": "2.3.8-3.1build1"
}
]
}{
"binaries": [
{
"binary_name": "libmotif-common",
"binary_version": "2.3.8-4"
},
{
"binary_name": "libmotif-dev",
"binary_version": "2.3.8-4"
},
{
"binary_name": "libmrm4",
"binary_version": "2.3.8-4"
},
{
"binary_name": "libuil4",
"binary_version": "2.3.8-4"
},
{
"binary_name": "libxm4",
"binary_version": "2.3.8-4"
},
{
"binary_name": "mwm",
"binary_version": "2.3.8-4"
},
{
"binary_name": "uil",
"binary_version": "2.3.8-4"
}
]
}{
"binaries": [
{
"binary_name": "libmotif-common",
"binary_version": "2.3.8-5"
},
{
"binary_name": "libmotif-dev",
"binary_version": "2.3.8-5"
},
{
"binary_name": "libmrm4",
"binary_version": "2.3.8-5"
},
{
"binary_name": "libuil4",
"binary_version": "2.3.8-5"
},
{
"binary_name": "libxm4",
"binary_version": "2.3.8-5"
},
{
"binary_name": "mwm",
"binary_version": "2.3.8-5"
},
{
"binary_name": "uil",
"binary_version": "2.3.8-5"
}
]
}{
"binaries": [
{
"binary_name": "libxpm-dev",
"binary_version": "1:3.5.11-1ubuntu0.16.04.1+esm1"
},
{
"binary_name": "libxpm4",
"binary_version": "1:3.5.11-1ubuntu0.16.04.1+esm1"
},
{
"binary_name": "xpmutils",
"binary_version": "1:3.5.11-1ubuntu0.16.04.1+esm1"
}
],
"availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"
}