Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2011-3170 | First vendor Publication | 2011-08-19 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:H/Au:N/C:P/I:P/A:P) | |||
---|---|---|---|
Cvss Base Score | 5.1 | Attack Range | Network |
Cvss Impact Score | 6.4 | Attack Complexity | High |
Cvss Expoit Score | 4.9 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
The gif_read_lzw function in filter/image-gif.c in CUPS 1.4.8 and earlier does not properly handle the first code word in an LZW stream, which allows remote attackers to trigger a heap-based buffer overflow, and possibly execute arbitrary code, via a crafted stream, a different vulnerability than CVE-2011-2896. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3170 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-119 | Failure to Constrain Operations within the Bounds of a Memory Buffer |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:15027 | |||
Oval ID: | oval:org.mitre.oval:def:15027 | ||
Title: | USN-1207-1 -- CUPS vulnerabilities | ||
Description: | cups: Common UNIX Printing System - server - cupsys: Common UNIX Printing System - server An attacker could send crafted print jobs to CUPS and cause it to crash or run programs. | ||
Family: | unix | Class: | patch |
Reference(s): | USN-1207-1 CVE-2011-2896 CVE-2011-3170 | Version: | 5 |
Platform(s): | Ubuntu 11.04 Ubuntu 8.04 Ubuntu 10.04 Ubuntu 10.10 | Product(s): | CUPS |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:15349 | |||
Oval ID: | oval:org.mitre.oval:def:15349 | ||
Title: | DSA-2354-1 cups -- several | ||
Description: | Petr Sklenar and Tomas Hoger discovered that missing input sanitising in the GIF decoder inside the Cups printing system could lead to denial of service or potentially arbitrary code execution through crafted GIF files. | ||
Family: | unix | Class: | patch |
Reference(s): | DSA-2354-1 CVE-2011-2896 CVE-2011-3170 | Version: | 5 |
Platform(s): | Debian GNU/Linux 5.0 Debian GNU/Linux 6.0 Debian GNU/kFreeBSD 6.0 | Product(s): | cups |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
OpenVAS Exploits
Date | Description |
---|---|
2012-08-10 | Name : Gentoo Security Advisory GLSA 201207-10 (cups) File : nvt/glsa_201207_10.nasl |
2012-02-11 | Name : Debian Security Advisory DSA 2354-1 (cups) File : nvt/deb_2354_1.nasl |
2011-10-14 | Name : Mandriva Update for cups MDVSA-2011:146 (cups) File : nvt/gb_mandriva_MDVSA_2011_146.nasl |
2011-09-16 | Name : Ubuntu Update for cups USN-1207-1 File : nvt/gb_ubuntu_USN_1207_1.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
74673 | CUPS filter/image-gif.c gif_read_lzw Function Crafted LZW Stream Remote Overflow |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2012-09-06 | Name : The remote Mandriva Linux host is missing one or more security updates. File : mandriva_MDVSA-2011-147.nasl - Type : ACT_GATHER_INFO |
2012-07-10 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-201207-10.nasl - Type : ACT_GATHER_INFO |
2011-12-13 | Name : The remote SuSE 11 host is missing one or more security updates. File : suse_11_cups-110921.nasl - Type : ACT_GATHER_INFO |
2011-12-13 | Name : The remote SuSE 10 host is missing a security-related patch. File : suse_cups-7775.nasl - Type : ACT_GATHER_INFO |
2011-12-01 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-2354.nasl - Type : ACT_GATHER_INFO |
2011-10-24 | Name : The remote SuSE 10 host is missing a security-related patch. File : suse_cups-7774.nasl - Type : ACT_GATHER_INFO |
2011-10-11 | Name : The remote Mandriva Linux host is missing one or more security updates. File : mandriva_MDVSA-2011-146.nasl - Type : ACT_GATHER_INFO |
2011-09-15 | Name : The remote Ubuntu host is missing a security-related patch. File : ubuntu_USN-1207-1.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:04:23 |
|
2024-11-28 12:26:52 |
|
2024-02-16 12:15:31 |
|
2021-05-04 12:15:15 |
|
2021-04-22 01:16:48 |
|
2020-05-23 01:46:31 |
|
2020-05-23 00:30:57 |
|
2017-08-29 09:23:30 |
|
2016-04-26 21:01:43 |
|
2014-02-17 11:04:41 |
|
2013-05-16 17:02:47 |
|
2013-05-10 23:06:14 |
|