Description

A heap buffer overflow vulnerability has been identified in the lcms2-2.16. The vulnerability exists in the UnrollChunkyBytes function in cmspack.c, which is responsible for handling color space transformations. NOTE: this is disputed by the Supplier because the finding identified a bug in a third-party calling program, not in lcms.

INFO

Published Date :

2025-04-01T00:00:00.000Z

Last Modified :

2025-04-04T20:30:37.843Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2025-29069 vulnerability.

No data.

REFERENCES

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact