// For flags

CVE-2011-3170

Gentoo Linux Security Advisory 201207-10

Severity Score

8.8
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The gif_read_lzw function in filter/image-gif.c in CUPS 1.4.8 and earlier does not properly handle the first code word in an LZW stream, which allows remote attackers to trigger a heap-based buffer overflow, and possibly execute arbitrary code, via a crafted stream, a different vulnerability than CVE-2011-2896.

La función gif_read_lzw en filter/image-gif.c en CUPS v1.4.8 y anteriores no controla correctamente la primera WORD de código en un flujo LZW, lo que permite provocar un desbordamiento de búfer basado en memoria dinámica (heap) a atacantes remotos, y posiblemente, ejecutar código de su elección, a través de un stream debidamente modificado. Se trata de una vulnerabilidad diferente a la CVE-2011.2896.

The cupsDoAuthentication function in auth.c in the client in CUPS before 1.4.4, when HAVE_GSSAPI is omitted, does not properly handle a demand for authorization, which allows remote CUPS servers to cause a denial of service via HTTP_UNAUTHORIZED responses. The LZW decompressor in the LWZReadByte function in giftoppm.c in the David Koblas GIF decoder in PBMPLUS, as used in the gif_read_lzw function in filter/image-gif.c in CUPS before 1.4.7, the LZWReadByte function in plug-ins/common/file-gif-load.c in GIMP 2.6.11 and earlier, the LZWReadByte function in img/gifread.c in XPCE in SWI-Prolog 5.10.4 and earlier, and other products, does not properly handle code words that are absent from the decompression table when encountered, which allows remote attackers to trigger an infinite loop or a heap-based buffer overflow, and possibly execute arbitrary code, via a crafted compressed stream, a related issue to and CVE-2011-2895. The gif_read_lzw function in filter/image-gif.c in CUPS 1.4.8 and earlier does not properly handle the first code word in an LZW stream, which allows remote attackers to trigger a heap-based buffer overflow, and possibly execute arbitrary code, via a crafted stream, a different vulnerability than CVE-2011-2896.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
High
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2011-08-19 CVE Reserved
  • 2011-08-19 CVE Published
  • 2024-08-06 CVE Updated
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
<= 1.4.8
Search vendor "Apple" for product "Cups" and version " <= 1.4.8"
-
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.1
Search vendor "Apple" for product "Cups" and version "1.1"
-
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.1.1
Search vendor "Apple" for product "Cups" and version "1.1.1"
-
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.1.2
Search vendor "Apple" for product "Cups" and version "1.1.2"
-
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.1.3
Search vendor "Apple" for product "Cups" and version "1.1.3"
-
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.1.4
Search vendor "Apple" for product "Cups" and version "1.1.4"
-
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.1.5
Search vendor "Apple" for product "Cups" and version "1.1.5"
-
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.1.5-1
Search vendor "Apple" for product "Cups" and version "1.1.5-1"
-
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.1.5-2
Search vendor "Apple" for product "Cups" and version "1.1.5-2"
-
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.1.6
Search vendor "Apple" for product "Cups" and version "1.1.6"
-
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.1.6-1
Search vendor "Apple" for product "Cups" and version "1.1.6-1"
-
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.1.6-2
Search vendor "Apple" for product "Cups" and version "1.1.6-2"
-
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.1.6-3
Search vendor "Apple" for product "Cups" and version "1.1.6-3"
-
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.1.7
Search vendor "Apple" for product "Cups" and version "1.1.7"
-
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.1.8
Search vendor "Apple" for product "Cups" and version "1.1.8"
-
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.1.9
Search vendor "Apple" for product "Cups" and version "1.1.9"
-
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.1.9-1
Search vendor "Apple" for product "Cups" and version "1.1.9-1"
-
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.1.10
Search vendor "Apple" for product "Cups" and version "1.1.10"
-
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.1.10-1
Search vendor "Apple" for product "Cups" and version "1.1.10-1"
-
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.1.11
Search vendor "Apple" for product "Cups" and version "1.1.11"
-
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.1.12
Search vendor "Apple" for product "Cups" and version "1.1.12"
-
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.1.13
Search vendor "Apple" for product "Cups" and version "1.1.13"
-
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.1.14
Search vendor "Apple" for product "Cups" and version "1.1.14"
-
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.1.15
Search vendor "Apple" for product "Cups" and version "1.1.15"
-
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.1.16
Search vendor "Apple" for product "Cups" and version "1.1.16"
-
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.1.17
Search vendor "Apple" for product "Cups" and version "1.1.17"
-
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.1.18
Search vendor "Apple" for product "Cups" and version "1.1.18"
-
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.1.19
Search vendor "Apple" for product "Cups" and version "1.1.19"
-
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.1.19
Search vendor "Apple" for product "Cups" and version "1.1.19"
rc1
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.1.19
Search vendor "Apple" for product "Cups" and version "1.1.19"
rc2
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.1.19
Search vendor "Apple" for product "Cups" and version "1.1.19"
rc3
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.1.19
Search vendor "Apple" for product "Cups" and version "1.1.19"
rc4
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.1.19
Search vendor "Apple" for product "Cups" and version "1.1.19"
rc5
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.1.20
Search vendor "Apple" for product "Cups" and version "1.1.20"
-
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.1.20
Search vendor "Apple" for product "Cups" and version "1.1.20"
rc1
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.1.20
Search vendor "Apple" for product "Cups" and version "1.1.20"
rc2
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.1.20
Search vendor "Apple" for product "Cups" and version "1.1.20"
rc3
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.1.20
Search vendor "Apple" for product "Cups" and version "1.1.20"
rc4
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.1.20
Search vendor "Apple" for product "Cups" and version "1.1.20"
rc5
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.1.20
Search vendor "Apple" for product "Cups" and version "1.1.20"
rc6
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.1.21
Search vendor "Apple" for product "Cups" and version "1.1.21"
-
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.1.21
Search vendor "Apple" for product "Cups" and version "1.1.21"
rc1
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.1.21
Search vendor "Apple" for product "Cups" and version "1.1.21"
rc2
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.1.22
Search vendor "Apple" for product "Cups" and version "1.1.22"
-
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.1.22
Search vendor "Apple" for product "Cups" and version "1.1.22"
rc1
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.1.22
Search vendor "Apple" for product "Cups" and version "1.1.22"
rc2
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.1.23
Search vendor "Apple" for product "Cups" and version "1.1.23"
-
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.1.23
Search vendor "Apple" for product "Cups" and version "1.1.23"
rc1
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.2
Search vendor "Apple" for product "Cups" and version "1.2"
b1
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.2
Search vendor "Apple" for product "Cups" and version "1.2"
b2
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.2
Search vendor "Apple" for product "Cups" and version "1.2"
rc1
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.2
Search vendor "Apple" for product "Cups" and version "1.2"
rc2
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.2
Search vendor "Apple" for product "Cups" and version "1.2"
rc3
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.2.0
Search vendor "Apple" for product "Cups" and version "1.2.0"
-
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.2.1
Search vendor "Apple" for product "Cups" and version "1.2.1"
-
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.2.2
Search vendor "Apple" for product "Cups" and version "1.2.2"
-
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.2.3
Search vendor "Apple" for product "Cups" and version "1.2.3"
-
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.2.4
Search vendor "Apple" for product "Cups" and version "1.2.4"
-
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.2.5
Search vendor "Apple" for product "Cups" and version "1.2.5"
-
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.2.6
Search vendor "Apple" for product "Cups" and version "1.2.6"
-
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.2.7
Search vendor "Apple" for product "Cups" and version "1.2.7"
-
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.2.8
Search vendor "Apple" for product "Cups" and version "1.2.8"
-
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.2.9
Search vendor "Apple" for product "Cups" and version "1.2.9"
-
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.2.10
Search vendor "Apple" for product "Cups" and version "1.2.10"
-
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.2.11
Search vendor "Apple" for product "Cups" and version "1.2.11"
-
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.2.12
Search vendor "Apple" for product "Cups" and version "1.2.12"
-
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.3
Search vendor "Apple" for product "Cups" and version "1.3"
b1
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.3
Search vendor "Apple" for product "Cups" and version "1.3"
rc1
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.3
Search vendor "Apple" for product "Cups" and version "1.3"
rc2
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.3.0
Search vendor "Apple" for product "Cups" and version "1.3.0"
-
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.3.1
Search vendor "Apple" for product "Cups" and version "1.3.1"
-
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.3.2
Search vendor "Apple" for product "Cups" and version "1.3.2"
-
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.3.3
Search vendor "Apple" for product "Cups" and version "1.3.3"
-
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.3.4
Search vendor "Apple" for product "Cups" and version "1.3.4"
-
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.3.5
Search vendor "Apple" for product "Cups" and version "1.3.5"
-
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.3.6
Search vendor "Apple" for product "Cups" and version "1.3.6"
-
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.3.7
Search vendor "Apple" for product "Cups" and version "1.3.7"
-
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.3.8
Search vendor "Apple" for product "Cups" and version "1.3.8"
-
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.3.9
Search vendor "Apple" for product "Cups" and version "1.3.9"
-
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.3.10
Search vendor "Apple" for product "Cups" and version "1.3.10"
-
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.3.11
Search vendor "Apple" for product "Cups" and version "1.3.11"
-
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.4
Search vendor "Apple" for product "Cups" and version "1.4"
b1
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.4
Search vendor "Apple" for product "Cups" and version "1.4"
b2
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.4
Search vendor "Apple" for product "Cups" and version "1.4"
b3
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.4
Search vendor "Apple" for product "Cups" and version "1.4"
rc1
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.4.0
Search vendor "Apple" for product "Cups" and version "1.4.0"
-
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.4.1
Search vendor "Apple" for product "Cups" and version "1.4.1"
-
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.4.2
Search vendor "Apple" for product "Cups" and version "1.4.2"
-
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.4.3
Search vendor "Apple" for product "Cups" and version "1.4.3"
-
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.4.4
Search vendor "Apple" for product "Cups" and version "1.4.4"
-
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.4.5
Search vendor "Apple" for product "Cups" and version "1.4.5"
-
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.4.6
Search vendor "Apple" for product "Cups" and version "1.4.6"
-
Affected
Apple
Search vendor "Apple"
Cups
Search vendor "Apple" for product "Cups"
1.4.7
Search vendor "Apple" for product "Cups" and version "1.4.7"
-
Affected