CVE-2025-29070

A heap buffer overflow vulnerability has been identified in thesmooth2() in cmsgamma.c in lcms2-2.16 which allows a remote attacker to cause a denial of service. NOTE: the Supplier disputes this because "this is not exploitable as this function is never called on normal color management, is there only as a helper for low-level programming and investigation."
Configurations

No configuration.

History

04 Apr 2025, 21:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CWE CWE-122

04 Apr 2025, 02:15

Type Values Removed Values Added
References
  • () https://github.com/mm2/Little-CMS/issues/475#issuecomment-2696785063 -
Summary
  • (es) Se ha identificado una vulnerabilidad de desbordamiento de búfer de montón en thesmooth2() en cmsgamma.c en lcms2-2.16 que permite a un atacante remoto provocar una denegación de servicio.
Summary (en) A heap buffer overflow vulnerability has been identified in thesmooth2() in cmsgamma.c in lcms2-2.16 which allows a remote attacker to cause a denial of service. (en) A heap buffer overflow vulnerability has been identified in thesmooth2() in cmsgamma.c in lcms2-2.16 which allows a remote attacker to cause a denial of service. NOTE: the Supplier disputes this because "this is not exploitable as this function is never called on normal color management, is there only as a helper for low-level programming and investigation."

01 Apr 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-01 21:15

Updated : 2025-04-04 21:15


NVD link : CVE-2025-29070

Mitre link : CVE-2025-29070

CVE.ORG link : CVE-2025-29070


JSON object : View

Products Affected

No product.

CWE
CWE-122

Heap-based Buffer Overflow