The gif_read_lzw function in filter/image-gif.c in CUPS 1.4.8 and earlier does not properly handle the first code word in an LZW stream, which allows remote attackers to trigger a heap-based buffer overflow, and possibly execute arbitrary code, via a crafted stream, a different vulnerability than CVE-2011-2896.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade cups | Jul 30, 2024 | Aug 19, 2011 |
| Gentoo Linux | — | Upgrade net-print/cups. | Oct 30, 2017 | Aug 19, 2011 |
| Suse | — | Upgrade cups-libs-32bitUpgrade cups-libs-x86Upgrade cups-develUpgrade cupsUpgrade cups-libsUpgrade cups-client | Dec 12, 2013 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libcupsimage2 | Nov 8, 2024 | Aug 19, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub