A heap buffer overflow vulnerability has been identified in thesmooth2() in cmsgamma.c in lcms2-2.16 which allows a remote attacker to cause a denial of service. NOTE: the Supplier disputes this because "this is not exploitable as this function is never called on normal color management, is there only as a helper for low-level programming and investigation."
Metrics
Affected Vendors & Products
References
History
Fri, 04 Apr 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-122 | |
Metrics |
cvssV3_1
|
Fri, 04 Apr 2025 01:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A heap buffer overflow vulnerability has been identified in thesmooth2() in cmsgamma.c in lcms2-2.16 which allows a remote attacker to cause a denial of service. | A heap buffer overflow vulnerability has been identified in thesmooth2() in cmsgamma.c in lcms2-2.16 which allows a remote attacker to cause a denial of service. NOTE: the Supplier disputes this because "this is not exploitable as this function is never called on normal color management, is there only as a helper for low-level programming and investigation." |
References |
|
Tue, 01 Apr 2025 20:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A heap buffer overflow vulnerability has been identified in thesmooth2() in cmsgamma.c in lcms2-2.16 which allows a remote attacker to cause a denial of service. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-04-01T00:00:00.000Z
Updated: 2025-04-04T20:25:30.475Z
Reserved: 2025-03-11T00:00:00.000Z
Link: CVE-2025-29070

Updated: 2025-04-04T20:25:21.578Z

Status : Awaiting Analysis
Published: 2025-04-01T21:15:44.023
Modified: 2025-04-04T21:15:45.167
Link: CVE-2025-29070

No data.