CVE-2011-3170
published 2011-08-19CVE-2011-3170: The gif_read_lzw function in filter/image-gif.c in CUPS 1.4.8 and earlier does not properly handle the first code word in an LZW stream, which allows remote…
PriorityP334medium5.1CVSS 2.0
AVNACHAuNCPIPAP
EPSS
3.95%
89.3th percentile
The gif_read_lzw function in filter/image-gif.c in CUPS 1.4.8 and earlier does not properly handle the first code word in an LZW stream, which allows remote attackers to trigger a heap-based buffer overflow, and possibly execute arbitrary code, via a crafted stream, a different vulnerability than CVE-2011-2896.
Affected
73 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | cups | <= 1.4.8 | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
| apple | cups | — | — |
CVSS provenance
nvdv2.05.1MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
osv5.1MEDIUM
vendor_debian5.1MEDIUM
vendor_redhat5.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gq38-xj7p-vcm8: The gif_read_lzw function in filter/image-gif
ghsa_unreviewed·2022-05-17·CVSS 5.1
CVE-2011-3170 [MEDIUM] CWE-119 GHSA-gq38-xj7p-vcm8: The gif_read_lzw function in filter/image-gif
The gif_read_lzw function in filter/image-gif.c in CUPS 1.4.8 and earlier does not properly handle the first code word in an LZW stream, which allows remote attackers to trigger a heap-based buffer overflow, and possibly execute arbitrary code, via a crafted stream, a different vulnerability than CVE-2011-2896.
OSV
CVE-2011-3170: The gif_read_lzw function in filter/image-gif
osv·2011-08-19·CVSS 5.1
CVE-2011-3170 [MEDIUM] CVE-2011-3170: The gif_read_lzw function in filter/image-gif
The gif_read_lzw function in filter/image-gif.c in CUPS 1.4.8 and earlier does not properly handle the first code word in an LZW stream, which allows remote attackers to trigger a heap-based buffer overflow, and possibly execute arbitrary code, via a crafted stream, a different vulnerability than CVE-2011-2896.
Ubuntu
CUPS vulnerabilities
vendor_ubuntu·2011-09-14
CVE-2011-2896 CUPS vulnerabilities
Title: CUPS vulnerabilities
Summary: An attacker could send crafted print jobs to CUPS and cause it to crash or
run programs.
Tomas Hoger discovered that the CUPS image library incorrectly handled LZW
streams. A remote attacker could use this flaw to cause a denial of service
or possibly execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
cups: gif_read_lzw() does not properly handle first code word in an LZW stream, which may lead to arbitrary code execution
vendor_redhat·2011-08-04·CVSS 5.1
CVE-2011-3170 [MEDIUM] cups: gif_read_lzw() does not properly handle first code word in an LZW stream, which may lead to arbitrary code execution
cups: gif_read_lzw() does not properly handle first code word in an LZW stream, which may lead to arbitrary code execution
The gif_read_lzw function in filter/image-gif.c in CUPS 1.4.8 and earlier does not properly handle the first code word in an LZW stream, which allows remote attackers to trigger a heap-based buffer overflow, and possibly execute arbitrary code, via a crafted stream, a different vulnerability than CVE-2011-2896.
Statement: Not affected. This flaw was introduced in CUPS due to an incomplete fix for CVE-2011-2896, which was not applied to any CUPS packages in Red Hat Enterprise Linux.
Package: cups (Red Hat Enterprise Linux 4) - Not affected
Package: cups (Red Hat Enterprise Linux 5) - Not affected
Package: cups (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2011-3170: cups - The gif_read_lzw function in filter/image-gif.c in CUPS 1.4.8 and earlier does n...
vendor_debian·2011·CVSS 5.1
CVE-2011-3170 [MEDIUM] CVE-2011-3170: cups - The gif_read_lzw function in filter/image-gif.c in CUPS 1.4.8 and earlier does n...
The gif_read_lzw function in filter/image-gif.c in CUPS 1.4.8 and earlier does not properly handle the first code word in an LZW stream, which allows remote attackers to trigger a heap-based buffer overflow, and possibly execute arbitrary code, via a crafted stream, a different vulnerability than CVE-2011-2896.
Scope: local
bookworm: resolved (fixed in 1.5.0-8)
bullseye: resolved (fixed in 1.5.0-8)
forky: resolved (fixed in 1.5.0-8)
sid: resolved (fixed in 1.5.0-8)
trixie: resolved (fixed in 1.5.0-8)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-3170 cups: gif_read_lzw() foes not properly handle first code word in an LZW stream, which may lead to arbitrary code execution [fedora-all]
bugzilla·2011-08-19·CVSS 5.1
CVE-2011-3170 [MEDIUM] CVE-2011-3170 cups: gif_read_lzw() foes not properly handle first code word in an LZW stream, which may lead to arbitrary code execution [fedora-all]
CVE-2011-3170 cups: gif_read_lzw() foes not properly handle first code word in an LZW stream, which may lead to arbitrary code execution [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/update
Bugzilla
CVE-2011-3170 cups: gif_read_lzw() does not properly handle first code word in an LZW stream, which may lead to arbitrary code execution
bugzilla·2011-08-19·CVSS 5.1
CVE-2011-3170 [MEDIUM] CVE-2011-3170 cups: gif_read_lzw() does not properly handle first code word in an LZW stream, which may lead to arbitrary code execution
CVE-2011-3170 cups: gif_read_lzw() does not properly handle first code word in an LZW stream, which may lead to arbitrary code execution
Common Vulnerabilities and Exposures assigned an identifier CVE-2011-3170 to
the following vulnerability:
Name: CVE-2011-3170
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3170
Assigned: 20110819
Reference: http://cups.org/str.php?L3914
Reference: https://bugzilla.redhat.com/show_bug.cgi?id=727800
The gif_read_lzw function in filter/image-gif.c in CUPS 1.4.8 and
earlier does not properly handle the first code word in an LZW stream,
which allows remote attackers to trigger a heap-based buffer overflow,
and possibly execute arbitrary code, via a crafted stream, a different
vulnerability than CVE-2011-2896.
Discussion:
Created cups trackin
Bugzilla
CVE-2011-2896 David Koblas' GIF decoder LZW decoder buffer overflow
bugzilla·2011-08-03·CVSS 9.3
CVE-2011-2896 [CRITICAL] CVE-2011-2896 David Koblas' GIF decoder LZW decoder buffer overflow
CVE-2011-2896 David Koblas' GIF decoder LZW decoder buffer overflow
GIF image file format readers in various open source projects are based on the GIF decoder implementation written by David Koblas. This implementation contains a bug in the LZW decompressor, causing it to in correctly handle compressed streams that contain code words that were not yet added to the decompression table. LZW decompression has a special case (a KwKwK string) when code word may match the first free entry in the decompression table. The implementation used in this GIF reading code allows code words not only matching, but also exceeding the first free entry.
This problem is identical to a bug found in BSD compress (CVE-2011-2895, bug #727624), but given the unclear relationship between BSD compress and GIF deco
http://cups.org/str.php?L3914http://secunia.com/advisories/45796http://secunia.com/advisories/46024http://security.gentoo.org/glsa/glsa-201207-10.xmlhttp://www.debian.org/security/2011/dsa-2354http://www.mandriva.com/security/advisories?name=MDVSA-2011:146http://www.mandriva.com/security/advisories?name=MDVSA-2011:147http://www.securityfocus.com/bid/49323http://www.securitytracker.com/id?1025980http://www.ubuntu.com/usn/USN-1207-1https://bugzilla.redhat.com/show_bug.cgi?id=727800https://exchange.xforce.ibmcloud.com/vulnerabilities/69380http://cups.org/str.php?L3914http://secunia.com/advisories/45796http://secunia.com/advisories/46024http://security.gentoo.org/glsa/glsa-201207-10.xmlhttp://www.debian.org/security/2011/dsa-2354http://www.mandriva.com/security/advisories?name=MDVSA-2011:146http://www.mandriva.com/security/advisories?name=MDVSA-2011:147http://www.securityfocus.com/bid/49323http://www.securitytracker.com/id?1025980http://www.ubuntu.com/usn/USN-1207-1https://bugzilla.redhat.com/show_bug.cgi?id=727800https://exchange.xforce.ibmcloud.com/vulnerabilities/69380
2011-08-19
Published