CVE-2011-2895
libxfont - buffer overflow
EPSS 8.4%
描述
The LZW decompressor in (1) the BufCompressedFill function in fontfile/decompress.c in X.Org libXfont before 1.4.4 and (2) compress/compress.c in 4.3BSD, as used in zopen.c in OpenBSD before 3.8, FreeBSD, NetBSD 4.0.x and 5.0.x before 5.0.3 and 5.1.x before 5.1.1, FreeType 2.1.9, and other products, does not properly handle code words that are absent from the decompression table when encountered, which allows context-dependent attackers to trigger an infinite loop or a heap-based buffer overflow, and possibly execute arbitrary code, via a crafted compressed stream, a related issue to CVE-2006-1168 and CVE-2011-2896.
如何修補 CVE-2011-2895
要修補 CVE-2011-2895,請將受影響套件升級到下列已修補版本。
- —升級至 1:1.4.4-1 或更新版本
- —升級至 1:1.3.3-2 或更新版本
CVE-2011-2895 正在被利用嗎?
中等 — EPSS 為 8.4%,可持續追蹤但非最高優先。
受影響套件(2)
- from 0, < 1:1.4.4-1
- from 0, < 1:1.3.3-2