Lucene search

K
cve[email protected]CVE-2011-3170
HistoryAug 19, 2011 - 5:55 p.m.

CVE-2011-3170

2011-08-1917:55:03
CWE-119
web.nvd.nist.gov
61
cups
buffer overflow
remote attack
cve-2011-3170
nvd

5.1 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

9.6 High

AI Score

Confidence

High

0.557 Medium

EPSS

Percentile

97.7%

The gif_read_lzw function in filter/image-gif.c in CUPS 1.4.8 and earlier does not properly handle the first code word in an LZW stream, which allows remote attackers to trigger a heap-based buffer overflow, and possibly execute arbitrary code, via a crafted stream, a different vulnerability than CVE-2011-2896.

Affected configurations

NVD
Node
applecupsRange1.4.8
OR
applecupsMatch1.1
OR
applecupsMatch1.1.1
OR
applecupsMatch1.1.2
OR
applecupsMatch1.1.3
OR
applecupsMatch1.1.4
OR
applecupsMatch1.1.5
OR
applecupsMatch1.1.5-1
OR
applecupsMatch1.1.5-2
OR
applecupsMatch1.1.6
OR
applecupsMatch1.1.6-1
OR
applecupsMatch1.1.6-2
OR
applecupsMatch1.1.6-3
OR
applecupsMatch1.1.7
OR
applecupsMatch1.1.8
OR
applecupsMatch1.1.9
OR
applecupsMatch1.1.9-1
OR
applecupsMatch1.1.10
OR
applecupsMatch1.1.10-1
OR
applecupsMatch1.1.11
OR
applecupsMatch1.1.12
OR
applecupsMatch1.1.13
OR
applecupsMatch1.1.14
OR
applecupsMatch1.1.15
OR
applecupsMatch1.1.16
OR
applecupsMatch1.1.17
OR
applecupsMatch1.1.18
OR
applecupsMatch1.1.19
OR
applecupsMatch1.1.19rc1
OR
applecupsMatch1.1.19rc2
OR
applecupsMatch1.1.19rc3
OR
applecupsMatch1.1.19rc4
OR
applecupsMatch1.1.19rc5
OR
applecupsMatch1.1.20
OR
applecupsMatch1.1.20rc1
OR
applecupsMatch1.1.20rc2
OR
applecupsMatch1.1.20rc3
OR
applecupsMatch1.1.20rc4
OR
applecupsMatch1.1.20rc5
OR
applecupsMatch1.1.20rc6
OR
applecupsMatch1.1.21
OR
applecupsMatch1.1.21rc1
OR
applecupsMatch1.1.21rc2
OR
applecupsMatch1.1.22
OR
applecupsMatch1.1.22rc1
OR
applecupsMatch1.1.22rc2
OR
applecupsMatch1.1.23
OR
applecupsMatch1.1.23rc1
OR
applecupsMatch1.2b1
OR
applecupsMatch1.2b2
OR
applecupsMatch1.2rc1
OR
applecupsMatch1.2rc2
OR
applecupsMatch1.2rc3
OR
applecupsMatch1.2.0
OR
applecupsMatch1.2.1
OR
applecupsMatch1.2.2
OR
applecupsMatch1.2.3
OR
applecupsMatch1.2.4
OR
applecupsMatch1.2.5
OR
applecupsMatch1.2.6
OR
applecupsMatch1.2.7
OR
applecupsMatch1.2.8
OR
applecupsMatch1.2.9
OR
applecupsMatch1.2.10
OR
applecupsMatch1.2.11
OR
applecupsMatch1.2.12
OR
applecupsMatch1.3b1
OR
applecupsMatch1.3rc1
OR
applecupsMatch1.3rc2
OR
applecupsMatch1.3.0
OR
applecupsMatch1.3.1
OR
applecupsMatch1.3.2
OR
applecupsMatch1.3.3
OR
applecupsMatch1.3.4
OR
applecupsMatch1.3.5
OR
applecupsMatch1.3.6
OR
applecupsMatch1.3.7
OR
applecupsMatch1.3.8
OR
applecupsMatch1.3.9
OR
applecupsMatch1.3.10
OR
applecupsMatch1.3.11
OR
applecupsMatch1.4b1
OR
applecupsMatch1.4b2
OR
applecupsMatch1.4b3
OR
applecupsMatch1.4rc1
OR
applecupsMatch1.4.0
OR
applecupsMatch1.4.1
OR
applecupsMatch1.4.2
OR
applecupsMatch1.4.3
OR
applecupsMatch1.4.4
OR
applecupsMatch1.4.5
OR
applecupsMatch1.4.6
OR
applecupsMatch1.4.7

5.1 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

9.6 High

AI Score

Confidence

High

0.557 Medium

EPSS

Percentile

97.7%