Heap-based Buffer Overflow in CUPS Product by Apple
CVE-2011-3170

Currently unrated

Key Information:

Vendor
Apple
Status
Vendor
CVE Published:
19 August 2011

Summary

The gif_read_lzw function within filter/image-gif.c of CUPS versions 1.4.8 and earlier is susceptible to a heap-based buffer overflow due to improper handling of the first code word in an LZW stream. This flaw can be exploited by remote attackers to potentially execute arbitrary code through a specially crafted LZW stream, exposing systems running affected versions of CUPS to serious security risks.

References

EPSS Score

7% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.