CVE Database
/

CVE-2011-2896

Back to search

CVE-2011-2896

Published: Aug 19, 2011

Modified: Aug 6, 2024

PUBLISHED

Description

The LZW decompressor in the LWZReadByte function in giftoppm.c in the David Koblas GIF decoder in PBMPLUS, as used in the gif_read_lzw function in filter/image-gif.c in CUPS before 1.4.7, the LZWReadByte function in plug-ins/common/file-gif-load.c in GIMP 2.6.11 and earlier, the LZWReadByte function in img/gifread.c in XPCE in SWI-Prolog 5.10.4 and earlier, and other products, does not properly handle code words that are absent from the decompression table when encountered, which allows remote attackers to trigger an infinite loop or a heap-based buffer overflow, and possibly execute arbitrary code, via a crafted compressed stream, a related issue to CVE-2006-1168 and CVE-2011-2895.

VendorProductVersions

n/a

n/a

affected
n/a

References

DSA-2426
vendor-advisory
x_refsource_DEBIAN
FEDORA-2011-11318
vendor-advisory
x_refsource_FEDORA
GLSA-201209-23
vendor-advisory
x_refsource_GENTOO
USN-1207-1
vendor-advisory
x_refsource_UBUNTU
RHSA-2012:1180
vendor-advisory
x_refsource_REDHAT
48308
third-party-advisory
x_refsource_SECUNIA
DSA-2354
vendor-advisory
x_refsource_DEBIAN
45948
third-party-advisory
x_refsource_SECUNIA
RHSA-2012:1181
vendor-advisory
x_refsource_REDHAT
46024
third-party-advisory
x_refsource_SECUNIA
45900
third-party-advisory
x_refsource_SECUNIA
RHSA-2011:1635
vendor-advisory
x_refsource_REDHAT
FEDORA-2011-11221
vendor-advisory
x_refsource_FEDORA
FEDORA-2011-11173
vendor-advisory
x_refsource_FEDORA
49148
vdb-entry
x_refsource_BID
MDVSA-2011:146
vendor-advisory
x_refsource_MANDRIVA
FEDORA-2011-11305
vendor-advisory
x_refsource_FEDORA
USN-1214-1
vendor-advisory
x_refsource_UBUNTU
50737
third-party-advisory
x_refsource_SECUNIA
MDVSA-2011:167
vendor-advisory
x_refsource_MANDRIVA
FEDORA-2011-11197
vendor-advisory
x_refsource_FEDORA
FEDORA-2011-11229
vendor-advisory
x_refsource_FEDORA
48236
third-party-advisory
x_refsource_SECUNIA
1025929
vdb-entry
x_refsource_SECTRACK
45621
third-party-advisory
x_refsource_SECUNIA
45945
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now