BSD compress LZW decoder buffer overflow
Published Aug 19, 2011
9.3
HIGHCVSS 2.0
EPSS 8.36%
Description
The LZW decompressor in (1) the BufCompressedFill function in fontfile/decompress.c in X.Org libXfont before 1.4.4 and (2) compress/compress.c in 4.3BSD, as used in zopen.c in OpenBSD before 3.8, FreeBSD, NetBSD 4.0.x and 5.0.x before 5.0.3 and 5.1.x before 5.1.1, FreeType 2.1.9, and other products, does not properly handle code words that are absent from the decompression table when encountered, which allows context-dependent attackers to trigger an infinite loop or a heap-based buffer overflow, and possibly execute arbitrary code, via a crafted compressed stream, a related issue to CVE-2006-1168 and CVE-2011-2896.
Affected products
No data.
- 2.1.9
- ≤ 1.4.3
- 1.2.0
- 1.2.1
- 1.2.2
- 1.2.3
- 1.2.4
- 1.2.5
- 1.2.6
- 1.2.7
- 1.2.8
- 1.2.9
- 1.3.0
- 1.3.1
- 1.3.2
- 1.3.3
- 1.3.4
- 1.4.0
- 1.4.1
- 1.4.2
- n/a
- n/a
- ≤ 3.7
- 2.0
- 2.1
- 2.2
- 2.3
- 2.4
- 2.5
- 2.6
- 2.7
- 2.8
- 2.9
- 3.0
- 3.1
- 3.2
- 3.3
- 3.4
- 3.5
- 3.6
No data.
Red Hat Enterprise Linux 4
freetype-0:2.1.9-19.el4
Fixed · RHSA-2011:1161
Red Hat Enterprise Linux 4
xorg-x11-0:6.8.2-1.EL.69
Fixed · RHSA-2011:1155
Red Hat Enterprise Linux 5
libXfont-0:1.2.2-1.0.4.el5_7
Fixed · RHSA-2011:1154
Red Hat Enterprise Linux 5.6 EUS - Server Only
libXfont-0:1.2.2-1.0.3.el5_6
Fixed · RHSA-2011:1834
Red Hat Enterprise Linux 6
libXfont-0:1.4.1-2.el6_1
Fixed · RHSA-2011:1154
Red Hat Enterprise Linux 4
busybox
Not affected
Red Hat Enterprise Linux 4
gzip
Not affected
Red Hat Enterprise Linux 4
mailx
Not affected
Red Hat Enterprise Linux 4
ncompress
Not affected
Red Hat Enterprise Linux 5
busybox
Not affected
Red Hat Enterprise Linux 5
freetype
Not affected
Red Hat Enterprise Linux 5
gzip
Not affected
Red Hat Enterprise Linux 5
mailx
Not affected
Red Hat Enterprise Linux 5
ncompress
Not affected
Red Hat Enterprise Linux 6
busybox
Not affected
Red Hat Enterprise Linux 6
freetype
Not affected
Red Hat Enterprise Linux 6
gzip
Not affected
Red Hat Enterprise Linux 6
libarchive
Not affected
Red Hat Enterprise Linux 6
mailx
Will not fix
Red Hat Enterprise Linux 6
ncompress
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 4 | freetype-0:2.1.9-19.el4 | Fixed | RHSA-2011:1161 |
| Red Hat Enterprise Linux 4 | xorg-x11-0:6.8.2-1.EL.69 | Fixed | RHSA-2011:1155 |
| Red Hat Enterprise Linux 5 | libXfont-0:1.2.2-1.0.4.el5_7 | Fixed | RHSA-2011:1154 |
| Red Hat Enterprise Linux 5.6 EUS - Server Only | libXfont-0:1.2.2-1.0.3.el5_6 | Fixed | RHSA-2011:1834 |
| Red Hat Enterprise Linux 6 | libXfont-0:1.4.1-2.el6_1 | Fixed | RHSA-2011:1154 |
| Red Hat Enterprise Linux 4 | busybox | Not affected | n/a |
| Red Hat Enterprise Linux 4 | gzip | Not affected | n/a |
| Red Hat Enterprise Linux 4 | mailx | Not affected | n/a |
| Red Hat Enterprise Linux 4 | ncompress | Not affected | n/a |
| Red Hat Enterprise Linux 5 | busybox | Not affected | n/a |
| Red Hat Enterprise Linux 5 | freetype | Not affected | n/a |
| Red Hat Enterprise Linux 5 | gzip | Not affected | n/a |
| Red Hat Enterprise Linux 5 | mailx | Not affected | n/a |
| Red Hat Enterprise Linux 5 | ncompress | Not affected | n/a |
| Red Hat Enterprise Linux 6 | busybox | Not affected | n/a |
| Red Hat Enterprise Linux 6 | freetype | Not affected | n/a |
| Red Hat Enterprise Linux 6 | gzip | Not affected | n/a |
| Red Hat Enterprise Linux 6 | libarchive | Not affected | n/a |
| Red Hat Enterprise Linux 6 | mailx | Will not fix | n/a |
| Red Hat Enterprise Linux 6 | ncompress | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (16 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 8.36% (0.08355) | 94.80th | v5 (v2026.06.15) |
| Jun 15, 2026 | 8.36% (0.08355) | 94.22th | v5 (v2026.06.15) |
| Jul 20, 2025 | 6.37% (0.06374) | 90.56th | v4 (v2025.03.14) |
| Mar 30, 2025 | 8.80% (0.08801) | 91.70th | v4 (v2025.03.14) |
| Mar 29, 2025 | 19.14% (0.19143) | 92.37th | v4 (v2025.03.14) |
| Mar 19, 2025 | 8.80% (0.08801) | 91.46th | v4 (v2025.03.14) |
| Mar 17, 2025 | 10.39% (0.10392) | 92.64th | v4 (v2025.03.14) |
| Dec 12, 2024 | 1.33% (0.01330) | 86.60th | v3 (v2023.03.01) |
| May 28, 2024 | 1.33% (0.01330) | 86.00th | v3 (v2023.03.01) |
| Apr 8, 2024 | 1.34% (0.01336) | 85.80th | v3 (v2023.03.01) |
| Mar 7, 2023 | 1.21% (0.01205) | 83.03th | v3 (v2023.03.01) |
| Mar 6, 2023 | 4.42% (0.04421) | 88.21th | v2 (v2022.01.01) |
| Feb 13, 2023 | 4.42% (0.04421) | 87.82th | v2 (v2022.01.01) |
| Feb 3, 2023 | 2.69% (0.02686) | 82.44th | v2 (v2022.01.01) |
| Apr 1, 2022 | 4.42% (0.04421) | 87.03th | v2 (v2022.01.01) |
| Feb 4, 2022 | 4.42% (0.04421) | 70.83th | v2 (v2022.01.01) |
References (41)
- http://cgit.freedesktop.org/xorg/lib/libXfont/commit/?id=d11ee5886e9d9ec610051a206b135a4cdc1e09a0 x_refsource_CONFIRMPatch
- http://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2011-007.txt.asc vendor-advisoryx_refsource_NETBSD
- http://lists.apple.com/archives/security-announce/2012/Feb/msg00000.html vendor-advisoryx_refsource_APPLE
- http://lists.apple.com/archives/security-announce/2012/May/msg00001.html vendor-advisoryx_refsource_APPLE
- http://lists.apple.com/archives/security-announce/2015/Dec/msg00000.html vendor-advisoryx_refsource_APPLE
- http://lists.apple.com/archives/security-announce/2015/Dec/msg00001.html vendor-advisoryx_refsource_APPLE
- http://lists.apple.com/archives/security-announce/2015/Dec/msg00002.html vendor-advisoryx_refsource_APPLE
- http://lists.apple.com/archives/security-announce/2015/Dec/msg00005.html vendor-advisoryx_refsource_APPLE
- http://lists.freedesktop.org/archives/xorg-announce/2011-August/001721.html mailing-listx_refsource_MLISTPatch
- http://lists.freedesktop.org/archives/xorg-announce/2011-August/001722.html mailing-listx_refsource_MLISTPatch
- http://lists.opensuse.org/opensuse-security-announce/2011-09/msg00019.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2011-12/msg00004.html vendor-advisoryx_refsource_SUSE
- http://secunia.com/advisories/45544 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/45568 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/45599 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/45986 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/46127 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/48951 third-party-advisoryx_refsource_SECUNIA
- http://securitytracker.com/id?1025920 vdb-entryx_refsource_SECTRACK
- http://support.apple.com/kb/HT5130 x_refsource_CONFIRM
- http://support.apple.com/kb/HT5281 x_refsource_CONFIRM
- http://www.debian.org/security/2011/dsa-2293 vendor-advisoryx_refsource_DEBIAN
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:153 vendor-advisoryx_refsource_MANDRIVA
- http://www.openbsd.org/cgi-bin/cvsweb/src/usr.bin/compress/zopen.c#rev1.17 x_refsource_CONFIRM
- http://www.openwall.com/lists/oss-security/2011/08/10/10 mailing-listx_refsource_MLIST
- http://www.redhat.com/support/errata/RHSA-2011-1154.html vendor-advisoryx_refsource_REDHATVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2011-1155.html vendor-advisoryx_refsource_REDHATVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2011-1161.html vendor-advisoryx_refsource_REDHATVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2011-1834.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/bid/49124 vdb-entryx_refsource_BID
- http://www.ubuntu.com/usn/USN-1191-1 vendor-advisoryx_refsource_UBUNTU
- https://access.redhat.com/security/cve/CVE-2011-2895 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=725760 x_refsource_CONFIRMPatch
- https://bugzilla.redhat.com/show_bug.cgi?id=727624 x_refsource_CONFIRMIssue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/69141 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2011-2895
- https://support.apple.com/HT205635 x_refsource_CONFIRM
- https://support.apple.com/HT205637 x_refsource_CONFIRM
- https://support.apple.com/HT205640 x_refsource_CONFIRM
- https://support.apple.com/HT205641 x_refsource_CONFIRM
- https://www.cve.org/CVERecord?id=CVE-2011-2895
Change history (0)
No recorded changes yet.