CVE-2011-2896
cups - several
描述
The LZW decompressor in the LWZReadByte function in giftoppm.c in the David Koblas GIF decoder in PBMPLUS, as used in the gif_read_lzw function in filter/image-gif.c in CUPS before 1.4.7, the LZWReadByte function in plug-ins/common/file-gif-load.c in GIMP 2.6.11 and earlier, the LZWReadByte function in img/gifread.c in XPCE in SWI-Prolog 5.10.4 and earlier, and other products, does not properly handle code words that are absent from the decompression table when encountered, which allows remote attackers to trigger an infinite loop or a heap-based buffer overflow, and possibly execute arbitrary code, via a crafted compressed stream, a related issue to CVE-2006-1168 and CVE-2011-2895.
如何修補 CVE-2011-2896
要修補 CVE-2011-2896,請將受影響套件升級到下列已修補版本。
- —升級至 1.5.0-8 或更新版本
- —升級至 1.4.4-7+squeeze1 或更新版本
- —升級至 2.6.11-5 或更新版本
CVE-2011-2896 正在被利用嗎?
中等 — EPSS 為 12.7%,可持續追蹤但非最高優先。
受影響套件(3)
- from 0, < 1.5.0-8
- from 0, < 1.4.4-7+squeeze1
- from 0, < 2.6.11-5