← Vulnerability feed

Vulnerability record · CVE-2011-2896 · published 19 August 2011

CVE-2011-2896: Swi-prolog out-of-bounds write vulnerability

Swi Prolog · Swi Prolog

The LZW decompressor in the LWZReadByte function in giftoppm.c in the David Koblas GIF decoder in PBMPLUS, as used in the gif_read_lzw function in filter/image-gif.c in CUPS before 1.4.7, the LZWReadByte function in plug-ins/common/file-gif-load.c in GIMP 2.6.11 and earlier, the LZWReadByte function in img/gifread.c in XPCE in SWI-Prolog 5.10.4 and earlier, and other products, does not properly handle code words that are absent from the decompression table when encountered, which allows remote attackers to trigger an infinite loop or a heap-based buffer overflow, and possibly execute arbitrary code, via a crafted compressed stream, a related issue to CVE-2006-1168 and CVE-2011-2895.

5.1 CVSS 2.0 Medium EPSS 12% · top 4.0% CWE-787 · Out-of-bounds write
5.1CVSS 2.0 base score
12%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
64References
16 Jun 2026Last modified by NVD

Description

The LZW decompressor in the LWZReadByte function in giftoppm.c in the David Koblas GIF decoder in PBMPLUS, as used in the gif_read_lzw function in filter/image-gif.c in CUPS before 1.4.7, the LZWReadByte function in plug-ins/common/file-gif-load.c in GIMP 2.6.11 and earlier, the LZWReadByte function in img/gifread.c in XPCE in SWI-Prolog 5.10.4 and earlier, and other products, does not properly handle code words that are absent from the decompression table when encountered, which allows remote attackers to trigger an infinite loop or a heap-based buffer overflow, and possibly execute arbitrary code, via a crafted compressed stream, a related issue to CVE-2006-1168 and CVE-2011-2895.

AV:N/AC:H/Au:N/C:P/I:P/A:P

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://cups.org/str.php?L3867 PatchThird Party Advisory
http://git.gnome.org/browse/gimp/commit/?id=376ad788c1a1c31d40f18494889c383f6909ebfc PatchVendor Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2011-August/064600.html Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2011-August/064873.html Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2011-September/065527.html Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2011-September/065539.html Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2011-September/065550.html Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2011-September/065651.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2012-1180.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2012-1181.html Third Party Advisory
http://secunia.com/advisories/45621 Broken Link
http://secunia.com/advisories/45900 Broken Link
http://secunia.com/advisories/45945 Broken Link
http://secunia.com/advisories/45948 Broken Link
http://secunia.com/advisories/46024 Broken Link
http://secunia.com/advisories/48236 Broken Link
http://secunia.com/advisories/48308 Broken Link
http://secunia.com/advisories/50737 Broken Link
http://security.gentoo.org/glsa/glsa-201209-23.xml Third Party Advisory
http://www.debian.org/security/2011/dsa-2354 Third Party Advisory
http://www.debian.org/security/2012/dsa-2426 Third Party Advisory
http://www.mandriva.com/security/advisories?name=MDVSA-2011:146 Broken Link
http://www.mandriva.com/security/advisories?name=MDVSA-2011:167 Broken Link
http://www.openwall.com/lists/oss-security/2011/08/10/10 Mailing ListPatchThird Party Advisory
http://www.redhat.com/support/errata/RHSA-2011-1635.html Broken Link
http://www.securityfocus.com/bid/49148 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id?1025929 Broken LinkThird Party AdvisoryVDB Entry
http://www.swi-prolog.org/bugzilla/show_bug.cgi?id=7#c4 Issue TrackingThird Party Advisory
http://www.ubuntu.com/usn/USN-1207-1 Third Party Advisory
http://www.ubuntu.com/usn/USN-1214-1 Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=727800 Issue TrackingPatchThird Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=730338 Issue TrackingThird Party Advisory
http://cups.org/str.php?L3867 PatchThird Party Advisory
http://git.gnome.org/browse/gimp/commit/?id=376ad788c1a1c31d40f18494889c383f6909ebfc PatchVendor Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2011-August/064600.html Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2011-August/064873.html Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2011-September/065527.html Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2011-September/065539.html Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2011-September/065550.html Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2011-September/065651.html Third Party Advisory

Track CVE-2011-2896 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2008-5184Apple cups vulnerabilityThe web interface (cgi-bin/admin.c) in CUPS before 1.3.8 uses the guest username when a user is not logged on to the web server, which makes it easie…EPSS 3.7%10.0CVE-2008-3641Apple cups vulnerabilityThe Hewlett-Packard Graphics Language (HPGL) filter in CUPS before 1.3.9 allows remote attackers to execute arbitrary code via crafted pen width and …EPSS 24%10.0CVE-2008-0053Apple cups memory buffer overflow vulnerabilityMultiple buffer overflows in the HP-GL/2-to-PostScript filter in CUPS before 1.3.6 might allow remote attackers to execute arbitrary code via a craft…EPSS 8.3%9.9CVE-2026-59090Gimp vulnerabilityA flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsigned integer underflow in the `block_rem` variable, occurs when a user …EPSS 0.61%9.8CVE-2012-6094Apple cups incorrect authorization vulnerabilitycups (Common Unix Printing System) 'Listen localhost:631' option not honored correctly which could provide unauthorized access to the systemEPSS 2.1%9.8CVE-2010-2941Apple cups use after free vulnerabilityipp.c in cupsd in CUPS 1.4.4 and earlier does not properly allocate memory for attribute values with invalid string data types, which allows remote a…EPSS 6.4%9.8CVE-2004-2154Apple cups vulnerabilityCUPS before 1.1.21rc1 treats a Location directive in cupsd.conf as case sensitive, which allows attackers to bypass intended ACLs via a printer name …EPSS 2.1%9.3CVE-2010-4541Gimp out-of-bounds write vulnerabilityStack-based buffer overflow in the loadit function in plug-ins/common/sphere-designer.c in the SPHERE DESIGNER plugin in GIMP 2.6.11 allows user-assi…EPSS 6.8%

Source: NIST National Vulnerability Database (record CVE-2011-2896), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.