CVE-2025-29069

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-29069
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-29069.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-29069
Related
Withdrawn
2025-04-02T15:57:46.523301Z
Published
2025-04-01T20:15:17Z
Modified
2025-04-01T22:47:11.352103Z
Summary
[none]
Details

A heap buffer overflow vulnerability has been identified in the lcms2-2.16. The vulnerability exists in the UnrollChunkyBytes function in cmspack.c, which is responsible for handling color space transformations.

References

Affected packages

Debian:11 / lcms2

Package

Name
lcms2
Purl
pkg:deb/debian/lcms2?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.12~rc1-2
2.13.1-1
2.14-1
2.14-2
2.16-1
2.16-2

Ecosystem specific

{
    "urgency": "unimportant"
}

Debian:12 / lcms2

Package

Name
lcms2
Purl
pkg:deb/debian/lcms2?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.14-2
2.16-1
2.16-2

Ecosystem specific

{
    "urgency": "unimportant"
}

Debian:13 / lcms2

Package

Name
lcms2
Purl
pkg:deb/debian/lcms2?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.14-2
2.16-1
2.16-2

Ecosystem specific

{
    "urgency": "unimportant"
}