The LZW decompressor in the LWZReadByte function in giftoppm.c in the David Koblas GIF decoder in PBMPLUS, as used in the gif_read_lzw function in filter/image-gif.c in CUPS before 1.4.7, the LZWReadByte function in plug-ins/common/file-gif-load.c in GIMP 2.6.11 and earlier, the LZWReadByte function in img/gifread.c in XPCE in SWI-Prolog 5.10.4 and earlier, and other products, does not properly handle code words that are absent from the decompression table when encountered, which allows remote attackers to trigger an infinite loop or a heap-based buffer overflow, and possibly execute arbitrary code, via a crafted compressed stream, a related issue to CVE-2006-1168 and CVE-2011-2895.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade gimpUpgrade gimp-devel-toolsUpgrade gimp-libsUpgrade gimp-develUpgrade gimp-help-browser | Dec 1, 2016 | Aug 19, 2011 |
| Debian | — | Upgrade gimpUpgrade cups | Jul 30, 2024 | Aug 19, 2011 |
| Gentoo Linux | — | Upgrade media-gfx/gimp. | Oct 30, 2017 | Aug 19, 2011 |
| Oracle_linux | — | Upgrade gimp-libsUpgrade gimp-develUpgrade gimp | Oct 16, 2024 | Aug 19, 2011 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Aug 10, 2011 |
| Suse | — | Upgrade gimp-plugins-pythonUpgrade cups-libsUpgrade gimp-develUpgrade libgimp-2_0-0Upgrade cups-develUpgrade gimpUpgrade cups-clientUpgrade cups-libs-x86Upgrade libgimpui-2_0-0Upgrade cupsUpgrade gimp-langUpgrade cups-libs-32bit | Dec 12, 2013 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libcupsimage2Upgrade gimp | Nov 8, 2024 | Aug 19, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub