CVE Database
/

CVE-2011-2895

Back to search

CVE-2011-2895

Published: Aug 19, 2011

Modified: Aug 6, 2024

PUBLISHED

Description

The LZW decompressor in (1) the BufCompressedFill function in fontfile/decompress.c in X.Org libXfont before 1.4.4 and (2) compress/compress.c in 4.3BSD, as used in zopen.c in OpenBSD before 3.8, FreeBSD, NetBSD 4.0.x and 5.0.x before 5.0.3 and 5.1.x before 5.1.1, FreeType 2.1.9, and other products, does not properly handle code words that are absent from the decompression table when encountered, which allows context-dependent attackers to trigger an infinite loop or a heap-based buffer overflow, and possibly execute arbitrary code, via a crafted compressed stream, a related issue to CVE-2006-1168 and CVE-2011-2896.

VendorProductVersions

n/a

n/a

affected
n/a

References

RHSA-2011:1154
vendor-advisory
x_refsource_REDHAT
USN-1191-1
vendor-advisory
x_refsource_UBUNTU
45544
third-party-advisory
x_refsource_SECUNIA
APPLE-SA-2015-12-08-4
vendor-advisory
x_refsource_APPLE
MDVSA-2011:153
vendor-advisory
x_refsource_MANDRIVA
49124
vdb-entry
x_refsource_BID
45599
third-party-advisory
x_refsource_SECUNIA
RHSA-2011:1155
vendor-advisory
x_refsource_REDHAT
1025920
vdb-entry
x_refsource_SECTRACK
openSUSE-SU-2011:1299
vendor-advisory
x_refsource_SUSE
APPLE-SA-2015-12-08-3
vendor-advisory
x_refsource_APPLE
SUSE-SU-2011:1035
vendor-advisory
x_refsource_SUSE
APPLE-SA-2012-02-01-1
vendor-advisory
x_refsource_APPLE
46127
third-party-advisory
x_refsource_SECUNIA
45986
third-party-advisory
x_refsource_SECUNIA
RHSA-2011:1161
vendor-advisory
x_refsource_REDHAT
RHSA-2011:1834
vendor-advisory
x_refsource_REDHAT
xorg-lzw-bo(69141)
vdb-entry
x_refsource_XF
APPLE-SA-2015-12-08-1
vendor-advisory
x_refsource_APPLE
45568
third-party-advisory
x_refsource_SECUNIA
NetBSD-SA2011-007
vendor-advisory
x_refsource_NETBSD
48951
third-party-advisory
x_refsource_SECUNIA
APPLE-SA-2015-12-08-2
vendor-advisory
x_refsource_APPLE
APPLE-SA-2012-05-09-1
vendor-advisory
x_refsource_APPLE
DSA-2293
vendor-advisory
x_refsource_DEBIAN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now
CVE-2011-2895 - Security Vulnerability | QwikSec