CVE-2011-2896

N/A Unknown
Published: August 19, 2011 Modified: April 29, 2026
View on NVD

Description

The LZW decompressor in the LWZReadByte function in giftoppm.c in the David Koblas GIF decoder in PBMPLUS, as used in the gif_read_lzw function in filter/image-gif.c in CUPS before 1.4.7, the LZWReadByte function in plug-ins/common/file-gif-load.c in GIMP 2.6.11 and earlier, the LZWReadByte function in img/gifread.c in XPCE in SWI-Prolog 5.10.4 and earlier, and other products, does not properly handle code words that are absent from the decompression table when encountered, which allows remote attackers to trigger an infinite loop or a heap-based buffer overflow, and possibly execute arbitrary code, via a crafted compressed stream, a related issue to CVE-2006-1168 and CVE-2011-2895.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://cups.org/str.php?L3867
Source: secalert@redhat.com
Patch Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2012-1180.html
Source: secalert@redhat.com
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2012-1181.html
Source: secalert@redhat.com
Third Party Advisory
http://secunia.com/advisories/45621
Source: secalert@redhat.com
Broken Link
http://secunia.com/advisories/45900
Source: secalert@redhat.com
Broken Link
http://secunia.com/advisories/45945
Source: secalert@redhat.com
Broken Link
http://secunia.com/advisories/45948
Source: secalert@redhat.com
Broken Link
http://secunia.com/advisories/46024
Source: secalert@redhat.com
Broken Link
http://secunia.com/advisories/48236
Source: secalert@redhat.com
Broken Link
http://secunia.com/advisories/48308
Source: secalert@redhat.com
Broken Link
http://secunia.com/advisories/50737
Source: secalert@redhat.com
Broken Link
http://security.gentoo.org/glsa/glsa-201209-23.xml
Source: secalert@redhat.com
Third Party Advisory
http://www.debian.org/security/2011/dsa-2354
Source: secalert@redhat.com
Third Party Advisory
http://www.debian.org/security/2012/dsa-2426
Source: secalert@redhat.com
Third Party Advisory
http://www.openwall.com/lists/oss-security/2011/08/10/10
Source: secalert@redhat.com
Mailing List Patch Third Party Advisory
http://www.redhat.com/support/errata/RHSA-2011-1635.html
Source: secalert@redhat.com
Broken Link
http://www.securityfocus.com/bid/49148
Source: secalert@redhat.com
Broken Link Third Party Advisory VDB Entry
http://www.securitytracker.com/id?1025929
Source: secalert@redhat.com
Broken Link Third Party Advisory VDB Entry
http://www.swi-prolog.org/bugzilla/show_bug.cgi?id=7#c4
Source: secalert@redhat.com
Issue Tracking Third Party Advisory
http://www.ubuntu.com/usn/USN-1207-1
Source: secalert@redhat.com
Third Party Advisory
http://www.ubuntu.com/usn/USN-1214-1
Source: secalert@redhat.com
Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=727800
Source: secalert@redhat.com
Issue Tracking Patch Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=730338
Source: secalert@redhat.com
Issue Tracking Third Party Advisory
http://cups.org/str.php?L3867
Source: af854a3a-2127-422b-91ae-364da2661108
Patch Third Party Advisory
http://git.gnome.org/browse/gimp/commit/?id=376ad788c1a1c31d40f18494889c383f6909ebfc
Source: af854a3a-2127-422b-91ae-364da2661108
Patch Vendor Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2011-August/064600.html
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2011-August/064873.html
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2011-September/065527.html
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2011-September/065539.html
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2011-September/065550.html
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2011-September/065651.html
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2012-1180.html
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2012-1181.html
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
http://secunia.com/advisories/45621
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
http://secunia.com/advisories/45900
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
http://secunia.com/advisories/45945
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
http://secunia.com/advisories/45948
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
http://secunia.com/advisories/46024
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
http://secunia.com/advisories/48236
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
http://secunia.com/advisories/48308
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
http://secunia.com/advisories/50737
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
http://security.gentoo.org/glsa/glsa-201209-23.xml
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
http://www.debian.org/security/2011/dsa-2354
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
http://www.debian.org/security/2012/dsa-2426
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
http://www.mandriva.com/security/advisories?name=MDVSA-2011:146
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
http://www.mandriva.com/security/advisories?name=MDVSA-2011:167
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
http://www.openwall.com/lists/oss-security/2011/08/10/10
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List Patch Third Party Advisory
http://www.redhat.com/support/errata/RHSA-2011-1635.html
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
http://www.securityfocus.com/bid/49148
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link Third Party Advisory VDB Entry
http://www.securitytracker.com/id?1025929
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link Third Party Advisory VDB Entry
http://www.swi-prolog.org/bugzilla/show_bug.cgi?id=7#c4
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking Third Party Advisory
http://www.ubuntu.com/usn/USN-1207-1
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
http://www.ubuntu.com/usn/USN-1214-1
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=727800
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking Patch Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=730338
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking Third Party Advisory

64 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
12.7%
96th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

gimp apple swi-prolog