FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2011-2895

This CVE name corresponds to:

Entered Topic
2012-01-29 FreeBSD -- errors handling corrupt compress file in compress(1) and gzip(1)
2011-08-11 libXfont -- possible local privilege escalation

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2011-2895
Phase Assigned(20110727)

Description

The LZW decompressor in (1) the BufCompressedFill function in fontfile/decompress.c in X.Org libXfont before 1.4.4 and (2) compress/compress.c in 4.3BSD, as used in zopen.c in OpenBSD before 3.8, FreeBSD, NetBSD 4.0.x and 5.0.x before 5.0.3 and 5.1.x before 5.1.1, FreeType 2.1.9, and other products, does not properly handle code words that are absent from the decompression table when encountered, which allows context-dependent attackers to trigger an infinite loop or a heap-based buffer overflow, and possibly execute arbitrary code, via a crafted compressed stream, a related issue to CVE-2006-1168 and CVE-2011-2896.

References

Source Reference
MLIST [oss-security] 20110810 LZW decompression issues
MLIST [xorg-announce] 20110810 X.Org security advisory: libXfont LZW decompression heap corruption
MLIST [xorg-announce] 20110810 [ANNOUNCE] libXfont 1.4.4
CONFIRM http://cgit.freedesktop.org/xorg/lib/libXfont/commit/?id=d11ee5886e9d9ec610051a206b135a4cdc1e09a0
CONFIRM http://www.openbsd.org/cgi-bin/cvsweb/src/usr.bin/compress/zopen.c#rev1.17
CONFIRM https://bugzilla.redhat.com/show_bug.cgi?id=725760
CONFIRM https://bugzilla.redhat.com/show_bug.cgi?id=727624
CONFIRM http://support.apple.com/kb/HT5130
CONFIRM http://support.apple.com/kb/HT5281
CONFIRM https://support.apple.com/HT205635
CONFIRM https://support.apple.com/HT205637
CONFIRM https://support.apple.com/HT205640
CONFIRM https://support.apple.com/HT205641
APPLE APPLE-SA-2012-02-01-1
APPLE APPLE-SA-2012-05-09-1
APPLE APPLE-SA-2015-12-08-1
APPLE APPLE-SA-2015-12-08-2
APPLE APPLE-SA-2015-12-08-3
APPLE APPLE-SA-2015-12-08-4
DEBIAN DSA-2293
MANDRIVA MDVSA-2011:153
NETBSD NetBSD-SA2011-007
REDHAT RHSA-2011:1154
REDHAT RHSA-2011:1155
REDHAT RHSA-2011:1161
REDHAT RHSA-2011:1834
SUSE SUSE-SU-2011:1035
SUSE openSUSE-SU-2011:1299
UBUNTU USN-1191-1
BID 49124
SECTRACK 1025920
SECUNIA 45544
SECUNIA 45568
SECUNIA 45599
SECUNIA 45986
SECUNIA 46127
SECUNIA 48951
XF xorg-lzw-bo(69141)