Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2011-2896

Опубликовано: 19 авг. 2011
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 5.1

Описание

The LZW decompressor in the LWZReadByte function in giftoppm.c in the David Koblas GIF decoder in PBMPLUS, as used in the gif_read_lzw function in filter/image-gif.c in CUPS before 1.4.7, the LZWReadByte function in plug-ins/common/file-gif-load.c in GIMP 2.6.11 and earlier, the LZWReadByte function in img/gifread.c in XPCE in SWI-Prolog 5.10.4 and earlier, and other products, does not properly handle code words that are absent from the decompression table when encountered, which allows remote attackers to trigger an infinite loop or a heap-based buffer overflow, and possibly execute arbitrary code, via a crafted compressed stream, a related issue to CVE-2006-1168 and CVE-2011-2895.

РелизСтатусПримечание
artful

not-affected

1.5.0-5
bionic

not-affected

1.5.0-5
cosmic

not-affected

1.5.0-5
devel

not-affected

1.5.0-5
disco

not-affected

1.5.0-5
eoan

not-affected

1.5.0-5
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was not-affected [1.5.0-5]]
esm-infra/bionic

not-affected

1.5.0-5
esm-infra/focal

not-affected

1.5.0-5
esm-infra/xenial

not-affected

1.5.0-5

Показывать по

РелизСтатусПримечание
artful

DNE

bionic

DNE

cosmic

DNE

devel

DNE

disco

DNE

eoan

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

DNE

focal

DNE

groovy

DNE

Показывать по

РелизСтатусПримечание
artful

not-affected

2.6.11-2ubuntu4
bionic

not-affected

2.6.11-2ubuntu4
cosmic

not-affected

2.6.11-2ubuntu4
devel

not-affected

2.6.11-2ubuntu4
disco

not-affected

2.6.11-2ubuntu4
eoan

not-affected

2.6.11-2ubuntu4
esm-apps/bionic

not-affected

2.6.11-2ubuntu4
esm-apps/focal

not-affected

2.6.11-2ubuntu4
esm-apps/jammy

not-affected

2.6.11-2ubuntu4
esm-apps/noble

not-affected

2.6.11-2ubuntu4

Показывать по

РелизСтатусПримечание
artful

ignored

end of life
bionic

ignored

end of standard support, was needed
cosmic

ignored

end of life
devel

needed

disco

ignored

end of life
eoan

ignored

end of life
esm-apps/bionic

needed

esm-apps/focal

needed

esm-apps/jammy

needed

esm-apps/noble

needed

Показывать по

EPSS

Процентиль: 90%
0.05268
Низкий

5.1 Medium

CVSS2

Связанные уязвимости

redhat
около 14 лет назад

The LZW decompressor in the LWZReadByte function in giftoppm.c in the David Koblas GIF decoder in PBMPLUS, as used in the gif_read_lzw function in filter/image-gif.c in CUPS before 1.4.7, the LZWReadByte function in plug-ins/common/file-gif-load.c in GIMP 2.6.11 and earlier, the LZWReadByte function in img/gifread.c in XPCE in SWI-Prolog 5.10.4 and earlier, and other products, does not properly handle code words that are absent from the decompression table when encountered, which allows remote attackers to trigger an infinite loop or a heap-based buffer overflow, and possibly execute arbitrary code, via a crafted compressed stream, a related issue to CVE-2006-1168 and CVE-2011-2895.

nvd
почти 14 лет назад

The LZW decompressor in the LWZReadByte function in giftoppm.c in the David Koblas GIF decoder in PBMPLUS, as used in the gif_read_lzw function in filter/image-gif.c in CUPS before 1.4.7, the LZWReadByte function in plug-ins/common/file-gif-load.c in GIMP 2.6.11 and earlier, the LZWReadByte function in img/gifread.c in XPCE in SWI-Prolog 5.10.4 and earlier, and other products, does not properly handle code words that are absent from the decompression table when encountered, which allows remote attackers to trigger an infinite loop or a heap-based buffer overflow, and possibly execute arbitrary code, via a crafted compressed stream, a related issue to CVE-2006-1168 and CVE-2011-2895.

debian
почти 14 лет назад

The LZW decompressor in the LWZReadByte function in giftoppm.c in the ...

github
больше 3 лет назад

The LZW decompressor in the LWZReadByte function in giftoppm.c in the David Koblas GIF decoder in PBMPLUS, as used in the gif_read_lzw function in filter/image-gif.c in CUPS before 1.4.7, the LZWReadByte function in plug-ins/common/file-gif-load.c in GIMP 2.6.11 and earlier, the LZWReadByte function in img/gifread.c in XPCE in SWI-Prolog 5.10.4 and earlier, and other products, does not properly handle code words that are absent from the decompression table when encountered, which allows remote attackers to trigger an infinite loop or a heap-based buffer overflow, and possibly execute arbitrary code, via a crafted compressed stream, a related issue to CVE-2006-1168 and CVE-2011-2895.

oracle-oval
больше 13 лет назад

ELSA-2012-0302: cups security and bug fix update (LOW)

EPSS

Процентиль: 90%
0.05268
Низкий

5.1 Medium

CVSS2