CVE-2011-3170: Buffer Overflow
The gifreadlzw function in filter/image-gif.c in CUPS 1.4.8 and earlier does not properly handle the first code word in an LZW stream, which allows remote attackers to trigger a heap-based buffer overflow, and possibly execute arbitrary code, via a crafted stream, a different vulnerability than CVE-2011-2896.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-3170?
CVE-2011-3170 has a critical severity rating due to its potential for remote code execution through a heap-based buffer overflow.
How do I fix CVE-2011-3170?
To fix CVE-2011-3170, upgrade CUPS to version 1.4.8 or later, which addresses this vulnerability.
What versions of CUPS are affected by CVE-2011-3170?
CVE-2011-3170 affects CUPS versions 1.4.7 and earlier, as well as various older releases.
What type of vulnerability is CVE-2011-3170?
CVE-2011-3170 is a heap-based buffer overflow vulnerability found in the gif_read_lzw function of CUPS.
Can CVE-2011-3170 be exploited remotely?
Yes, CVE-2011-3170 can be exploited remotely by attackers using a crafted LZW stream.