Release date:
Updated on:
Affected Systems:
Easy Software Products CUPS 1.4.8
Description:
--------------------------------------------------------------------------------
Bugtraq id: 49323
Cve id: CVE-2011-3170
CUPS is a standard open-source printing system developed by Apple Inc. for Mac OS X and other UNIX-related operating systems.
CUPS has a heap buffer overflow vulnerability in the implementation of gif_read_lzw (). Remote attackers can exploit this vulnerability to execute arbitrary code or cause DoS in the affected applications.
Boundary errors in the "gif_read_lzw ()" function (filter/image-gif.c) can be exploited to cause heap buffer overflow through specially crafted GIF images. Gif_read_lzw () incorrectly processes the first code word in the LZW stream.
<* Source: Red Hat Security Response Team
Link: https://bugzilla.redhat.com/show_bug.cgi? Id = 732106
Http://secunia.com/advisories/45713/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Easy Software Products
----------------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.cups.org