Vulnerabilidad en El descompresor en LZW en varias aplicaciones (CVE-2011-2895)
Gravedad CVSS v2.0:
ALTA
Tipo:
CWE-119
Restricción de operaciones inapropiada dentro de los límites del búfer de la memoria
Fecha de publicación:
19/08/2011
Última modificación:
11/04/2025
Descripción
El descompresor en LZW en (1) la función BufCompressedFill en fontfile/decompress.c en X.Org libXfont antes de la versión v1.4.4 y (2) compress/compress.c en 4.3BSD, tal y como se utiliza en zopen.c en OpenBSD antes de la versión v3.8, FreeBSD, NetBSD, FreeType v2.1.9, y otros productos, no controla correctamente las palabras de código ausentes de la tabla de descompresión, lo que permite provocar un bucle infinito o un desbordamiento de búfer basado en memoria dinámica (heap) a atacantes (dependiendo del contexto) y posiblemente ejecutar código de su elección a través de un flujo comprimido debidamente modificado. Se trata de un problema relacionado con los CVE-2006-1168 y CVE-2011 2896.
Impacto
Puntuación base 2.0
9.30
Gravedad 2.0
ALTA
Productos y versiones vulnerables
| CPE | Desde | Hasta |
|---|---|---|
| cpe:2.3:a:freetype:freetype:2.1.9:*:*:*:*:*:*:* | ||
| cpe:2.3:a:x:libxfont:*:*:*:*:*:*:*:* | 1.4.3 (incluyendo) | |
| cpe:2.3:a:x:libxfont:1.2.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:x:libxfont:1.2.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:x:libxfont:1.2.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:x:libxfont:1.2.3:*:*:*:*:*:*:* | ||
| cpe:2.3:a:x:libxfont:1.2.4:*:*:*:*:*:*:* | ||
| cpe:2.3:a:x:libxfont:1.2.5:*:*:*:*:*:*:* | ||
| cpe:2.3:a:x:libxfont:1.2.6:*:*:*:*:*:*:* | ||
| cpe:2.3:a:x:libxfont:1.2.7:*:*:*:*:*:*:* | ||
| cpe:2.3:a:x:libxfont:1.2.8:*:*:*:*:*:*:* | ||
| cpe:2.3:a:x:libxfont:1.2.9:*:*:*:*:*:*:* | ||
| cpe:2.3:a:x:libxfont:1.3.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:x:libxfont:1.3.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:x:libxfont:1.3.2:*:*:*:*:*:*:* |
Para consultar la lista completa de nombres de CPE con productos y versiones, ver esta página
Referencias a soluciones, herramientas e información
- http://cgit.freedesktop.org/xorg/lib/libXfont/commit/?id=d11ee5886e9d9ec610051a206b135a4cdc1e09a0
- http://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2011-007.txt.asc
- http://lists.apple.com/archives/security-announce/2012/Feb/msg00000.html
- http://lists.apple.com/archives/security-announce/2012/May/msg00001.html
- http://lists.apple.com/archives/security-announce/2015/Dec/msg00000.html
- http://lists.apple.com/archives/security-announce/2015/Dec/msg00001.html
- http://lists.apple.com/archives/security-announce/2015/Dec/msg00002.html
- http://lists.apple.com/archives/security-announce/2015/Dec/msg00005.html
- http://lists.freedesktop.org/archives/xorg-announce/2011-August/001721.html
- http://lists.freedesktop.org/archives/xorg-announce/2011-August/001722.html
- http://lists.opensuse.org/opensuse-security-announce/2011-09/msg00019.html
- http://lists.opensuse.org/opensuse-security-announce/2011-12/msg00004.html
- http://secunia.com/advisories/45544
- http://secunia.com/advisories/45568
- http://secunia.com/advisories/45599
- http://secunia.com/advisories/45986
- http://secunia.com/advisories/46127
- http://secunia.com/advisories/48951
- http://securitytracker.com/id?1025920=
- http://support.apple.com/kb/HT5130
- http://support.apple.com/kb/HT5281
- http://www.debian.org/security/2011/dsa-2293
- http://www.mandriva.com/security/advisories?name=MDVSA-2011%3A153
- http://www.openbsd.org/cgi-bin/cvsweb/src/usr.bin/compress/zopen.c#rev1.17
- http://www.openwall.com/lists/oss-security/2011/08/10/10
- http://www.redhat.com/support/errata/RHSA-2011-1154.html
- http://www.redhat.com/support/errata/RHSA-2011-1155.html
- http://www.redhat.com/support/errata/RHSA-2011-1161.html
- http://www.redhat.com/support/errata/RHSA-2011-1834.html
- http://www.securityfocus.com/bid/49124
- http://www.ubuntu.com/usn/USN-1191-1
- https://bugzilla.redhat.com/show_bug.cgi?id=725760
- https://bugzilla.redhat.com/show_bug.cgi?id=727624
- https://exchange.xforce.ibmcloud.com/vulnerabilities/69141
- https://support.apple.com/HT205635
- https://support.apple.com/HT205637
- https://support.apple.com/HT205640
- https://support.apple.com/HT205641
- http://cgit.freedesktop.org/xorg/lib/libXfont/commit/?id=d11ee5886e9d9ec610051a206b135a4cdc1e09a0
- http://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2011-007.txt.asc
- http://lists.apple.com/archives/security-announce/2012/Feb/msg00000.html
- http://lists.apple.com/archives/security-announce/2012/May/msg00001.html
- http://lists.apple.com/archives/security-announce/2015/Dec/msg00000.html
- http://lists.apple.com/archives/security-announce/2015/Dec/msg00001.html
- http://lists.apple.com/archives/security-announce/2015/Dec/msg00002.html
- http://lists.apple.com/archives/security-announce/2015/Dec/msg00005.html
- http://lists.freedesktop.org/archives/xorg-announce/2011-August/001721.html
- http://lists.freedesktop.org/archives/xorg-announce/2011-August/001722.html
- http://lists.opensuse.org/opensuse-security-announce/2011-09/msg00019.html
- http://lists.opensuse.org/opensuse-security-announce/2011-12/msg00004.html
- http://secunia.com/advisories/45544
- http://secunia.com/advisories/45568
- http://secunia.com/advisories/45599
- http://secunia.com/advisories/45986
- http://secunia.com/advisories/46127
- http://secunia.com/advisories/48951
- http://securitytracker.com/id?1025920=
- http://support.apple.com/kb/HT5130
- http://support.apple.com/kb/HT5281
- http://www.debian.org/security/2011/dsa-2293
- http://www.mandriva.com/security/advisories?name=MDVSA-2011%3A153
- http://www.openbsd.org/cgi-bin/cvsweb/src/usr.bin/compress/zopen.c#rev1.17
- http://www.openwall.com/lists/oss-security/2011/08/10/10
- http://www.redhat.com/support/errata/RHSA-2011-1154.html
- http://www.redhat.com/support/errata/RHSA-2011-1155.html
- http://www.redhat.com/support/errata/RHSA-2011-1161.html
- http://www.redhat.com/support/errata/RHSA-2011-1834.html
- http://www.securityfocus.com/bid/49124
- http://www.ubuntu.com/usn/USN-1191-1
- https://bugzilla.redhat.com/show_bug.cgi?id=725760
- https://bugzilla.redhat.com/show_bug.cgi?id=727624
- https://exchange.xforce.ibmcloud.com/vulnerabilities/69141
- https://support.apple.com/HT205635
- https://support.apple.com/HT205637
- https://support.apple.com/HT205640
- https://support.apple.com/HT205641



