Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-9489 | A heap buffer overflow vulnerability has been identified in thesmooth2() in cmsgamma.c in lcms2-2.16 which allows a remote attacker to cause a denial of service. NOTE: the Supplier disputes this because "this is not exploitable as this function is never called on normal color management, is there only as a helper for low-level programming and investigation." |
Fri, 04 Apr 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-122 | |
| Metrics |
cvssV3_1
|
Fri, 04 Apr 2025 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A heap buffer overflow vulnerability has been identified in thesmooth2() in cmsgamma.c in lcms2-2.16 which allows a remote attacker to cause a denial of service. | A heap buffer overflow vulnerability has been identified in thesmooth2() in cmsgamma.c in lcms2-2.16 which allows a remote attacker to cause a denial of service. NOTE: the Supplier disputes this because "this is not exploitable as this function is never called on normal color management, is there only as a helper for low-level programming and investigation." |
| References |
|
Tue, 01 Apr 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A heap buffer overflow vulnerability has been identified in thesmooth2() in cmsgamma.c in lcms2-2.16 which allows a remote attacker to cause a denial of service. | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-04-04T20:25:30.475Z
Reserved: 2025-03-11T00:00:00.000Z
Link: CVE-2025-29070
Updated: 2025-04-04T20:25:21.578Z
Status : Deferred
Published: 2025-04-01T21:15:44.023
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-29070
No data.
OpenCVE Enrichment
No data.
EUVD