The LZW decompressor in (1) the BufCompressedFill function in fontfile/decompress.c in X.Org libXfont before 1.4.4 and (2) compress/compress.c in 4.3BSD, as used in zopen.c in OpenBSD before 3.8, FreeBSD, NetBSD 4.0.x and 5.0.x before 5.0.3 and 5.1.x before 5.1.1, FreeType 2.1.9, and other products, does not properly handle code words that are absent from the decompression table when encountered, which allows context-dependent attackers to trigger an infinite loop or a heap-based buffer overflow, and possibly execute arbitrary code, via a crafted compressed stream, a related issue to CVE-2006-1168 and CVE-2011-2896.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2011-08-19T17:00:00
Updated: 2024-08-06T23:15:31.486Z
Reserved: 2011-07-27T00:00:00
Link: CVE-2011-2895
Vulnrichment
No data.
NVD
Status : Modified
Published: 2011-08-19T17:55:03.037
Modified: 2024-11-21T01:29:13.317
Link: CVE-2011-2895
Redhat