5.1
CVSSv2

CVE-2011-3170

Published: 19/08/2011 Updated: 29/08/2017
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
VMScore: 454
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

The gif_read_lzw function in filter/image-gif.c in CUPS 1.4.8 and previous versions does not properly handle the first code word in an LZW stream, which allows remote malicious users to trigger a heap-based buffer overflow, and possibly execute arbitrary code, via a crafted stream, a different vulnerability than CVE-2011-2896.

Vulnerable Product Search on Vulmon Subscribe to Product

apple cups 1.4

apple cups 1.4.0

apple cups 1.1.5-1

apple cups 1.1.5-2

apple cups 1.1.9-1

apple cups 1.1.10-1

apple cups 1.1.15

apple cups 1.1.18

apple cups 1.1.19

apple cups 1.1.20

apple cups 1.1.22

apple cups 1.2

apple cups 1.2.8

apple cups 1.2.9

apple cups 1.4.1

apple cups 1.4.2

apple cups 1.1.6

apple cups 1.1.6-1

apple cups 1.1.10

apple cups 1.1.6-3

apple cups 1.1.17

apple cups 1.1.12

apple cups 1.1.21

apple cups 1.2.5

apple cups 1.2.4

apple cups 1.2.3

apple cups 1.2.10

apple cups 1.2.11

apple cups 1.3.11

apple cups 1.3.2

apple cups 1.4.5

apple cups 1.4.6

apple cups 1.4.3

apple cups 1.3.6

apple cups 1.1.2

apple cups 1.1.3

apple cups 1.1.6-2

apple cups 1.1.8

apple cups 1.1.11

apple cups 1.1.14

apple cups 1.1.23

apple cups 1.2.2

apple cups 1.2.6

apple cups 1.2.12

apple cups 1.3

apple cups 1.3.3

apple cups 1.3.4

apple cups 1.4.7

apple cups

apple cups 1.3.0

apple cups 1.3.1

apple cups 1.3.7

apple cups 1.3.10

apple cups 1.4.4

apple cups 1.1

apple cups 1.1.1

apple cups 1.1.4

apple cups 1.1.5

apple cups 1.1.9

apple cups 1.1.7

apple cups 1.1.16

apple cups 1.1.13

apple cups 1.2.1

apple cups 1.2.0

apple cups 1.3.9

apple cups 1.2.7

apple cups 1.3.5

apple cups 1.3.8

Vendor Advisories

An attacker could send crafted print jobs to CUPS and cause it to crash or run programs ...
Petr Sklenar and Tomas Hoger discovered that missing input sanitising in the GIF decoder inside the CUPS printing system could lead to denial of service or potentially arbitrary code execution through crafted GIF files For the oldstable distribution (lenny), this problem has been fixed in version 138-1+lenny10 For the stable distribution (squee ...