Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:38967
HistoryJan 23, 2023 - 7:36 p.m.

Remote Code Execution(RCE)

2023-01-2319:36:46
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
17
libxpm
remote code execution
file extensions
path environment variable
software

0.001 Low

EPSS

Percentile

47.2%

libxpm is vulnerable to Remote Code Execution(RCE). When processing .Z or .gz file extensions, the library calls external programs to compress and uncompress files. This could allow a malicious user to execute other programs by manipulating the PATH environment variable.