CVE-2025-29069: Buffer Overflow
A heap buffer overflow vulnerability has been identified in the lcms2-2.16. The vulnerability exists in the UnrollChunkyBytes function in cmspack.c, which is responsible for handling color space transformations. NOTE: this is disputed by the Supplier because the finding identified a bug in a third-party calling program, not in lcms.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-29069?
CVE-2025-29069 is classified as a high-severity vulnerability due to the potential for a heap buffer overflow that may allow for remote code execution.
How do I fix CVE-2025-29069?
To address CVE-2025-29069, users should update to a patched version of lcms2 that resolves the heap buffer overflow in the UnrollChunkyBytes function.
What software is affected by CVE-2025-29069?
CVE-2025-29069 affects the Little CMS library, specifically versions prior to the fix that addresses the vulnerability.
What are the potential consequences of CVE-2025-29069?
Exploitation of CVE-2025-29069 could lead to unauthorized access, system crashes, or execution of arbitrary code.
Is CVE-2025-29069 disputed by the supplier?
Yes, the supplier disputes the finding of CVE-2025-29069, indicating that there is a bug in a third-party component rather than in their software.