Vulnerability Description
The LZW decompressor in the LWZReadByte function in giftoppm.c in the David Koblas GIF decoder in PBMPLUS, as used in the gif_read_lzw function in filter/image-gif.c in CUPS before 1.4.7, the LZWReadByte function in plug-ins/common/file-gif-load.c in GIMP 2.6.11 and earlier, the LZWReadByte function in img/gifread.c in XPCE in SWI-Prolog 5.10.4 and earlier, and other products, does not properly handle code words that are absent from the decompression table when encountered, which allows remote attackers to trigger an infinite loop or a heap-based buffer overflow, and possibly execute arbitrary code, via a crafted compressed stream, a related issue to CVE-2006-1168 and CVE-2011-2895.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Swi-Prolog | Swi-Prolog | <= 5.10.4 |
| Apple | Cups | <= 1.4.6 |
| Gimp | Gimp | <= 2.6.11 |
Related Weaknesses (CWE)
References
- http://cups.org/str.php?L3867PatchThird Party Advisory
- http://git.gnome.org/browse/gimp/commit/?id=376ad788c1a1c31d40f18494889c383f6909PatchVendor Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2011-August/064600.htmThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2011-August/064873.htmThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2011-September/065527.Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2011-September/065539.Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2011-September/065550.Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2011-September/065651.Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2012-1180.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2012-1181.htmlThird Party Advisory
- http://secunia.com/advisories/45621Broken Link
- http://secunia.com/advisories/45900Broken Link
- http://secunia.com/advisories/45945Broken Link
- http://secunia.com/advisories/45948Broken Link
- http://secunia.com/advisories/46024Broken Link
FAQ
What is CVE-2011-2896?
CVE-2011-2896 is a vulnerability with a CVSS score of 5.1 (MEDIUM). The LZW decompressor in the LWZReadByte function in giftoppm.c in the David Koblas GIF decoder in PBMPLUS, as used in the gif_read_lzw function in filter/image-gif.c in CUPS before 1.4.7, the LZWReadB...
How severe is CVE-2011-2896?
CVE-2011-2896 has been rated MEDIUM with a CVSS base score of 5.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2011-2896?
Check the references section above for vendor advisories and patch information. Affected products include: Swi-Prolog Swi-Prolog, Apple Cups, Gimp Gimp.