CVE-2011-2895Improper Restriction of Operations within the Bounds of a Memory Buffer in Openbsd

Severity
9.3CRITICALNVD
CNA7.5OSV7.5
EPSS
7.0%
top 8.50%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 19
Latest updateMay 17

Description

The LZW decompressor in (1) the BufCompressedFill function in fontfile/decompress.c in X.Org libXfont before 1.4.4 and (2) compress/compress.c in 4.3BSD, as used in zopen.c in OpenBSD before 3.8, FreeBSD, NetBSD 4.0.x and 5.0.x before 5.0.3 and 5.1.x before 5.1.1, FreeType 2.1.9, and other products, does not properly handle code words that are absent from the decompression table when encountered, which allows context-dependent attackers to trigger an infinite loop or a heap-based buffer overflow

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages4 packages

Debianx.org/libxfont< 1:1.4.4-1+3
NVDx/libxfont1.4.3+18
NVDopenbsd/openbsd3.7+17

Patches

🔴Vulnerability Details

3
GHSA
GHSA-8hvp-h85w-jwq9: The LZW decompressor in (1) the BufCompressedFill function in fontfile/decompress2022-05-17
CVEList
CVE-2011-2895: The LZW decompressor in (1) the BufCompressedFill function in fontfile/decompress2011-08-19
OSV
CVE-2011-2895: The LZW decompressor in (1) the BufCompressedFill function in fontfile/decompress2011-08-19

📋Vendor Advisories

9
BSD
FreeBSD-SA-11:04.compress: Errors handling corrupt compress file in compress(1) and gzip(1)2011-09-28
Ubuntu
libXfont vulnerability2011-08-15
Red Hat
BSD compress LZW decoder buffer overflow2011-08-10
Red Hat
David Koblas' GIF decoder LZW decoder buffer overflow2011-08-10
Debian
CVE-2011-2895: libxfont - The LZW decompressor in (1) the BufCompressedFill function in fontfile/decompres...2011

💬Community

2
Bugzilla
CVE-2011-2895 libXfont: LZW decompression heap corruption / infinite loop [fedora-all]2011-08-11
Bugzilla
CVE-2011-2895 BSD compress LZW decoder buffer overflow2011-08-02