#22379 closed enhancement (fixed)
Fix CVE-2025-64503, CVE-2025-57812, and CVE-2025-64524 in cups-filters and libcupsfilters
| Reported by: | Douglas R. Reno | Owned by: | zeckma |
|---|---|---|---|
| Priority: | elevated | Milestone: | 13.0 |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
There were two vulnerabilities disclosed on oss-security this morning for libcupsfilters and cups-filters.
- libcupsfilters: CVE-2025-57812 (multiple TIFF-related issues including heap buffer overflows and multiple out-of-bounds reads)
- cups-filters: CVE-2025-64503 (out-of-bounds read in pdftoraster)
More information can be found at https://seclists.org/oss-sec/2025/q4/172 and https://seclists.org/oss-sec/2025/q4/173
Change History (8)
comment:1 by , 11 months ago
comment:2 by , 11 months ago
| Summary: | Fix CVE-2025-64503 and CVE-2025-57812 in cups-filters and libcupsfilters → Fix CVE-2025-64503, CVE-2025-57812, and CVE-2025-64524 in cups-filters and libcupsfilters |
|---|
Adding CVE-2025-64524 to the list, issued this morning.
Hi all, we have CVE-2025-64524 in cups-filters project regarding heap buffer overflow in rastertopclx reported by frostb1ten. Since the issue requires user to have additional permissions to install printer with PPD file calling rastertopclx filter and the filter is run under lp user which does not have root permissions, the vulnerability is Low with CVSS score 3.3 CVSS:3.1/AV:L/AC:L/PR:L/ UI:N/S:U/C:N/I:N/A:L . More details in the advisory: https://github.com/OpenPrinting/cups-filters/security/advisories/GHSA-rq44-2q5p-x3hv Commits with fixes in the project: master: https://github.com/OpenPrinting/cups-filters/commit/0fe46c511e81062575b05936f804eb18c9f0a011 1.x: https://github.com/OpenPrinting/cups-filters/commit/b03866fd2e251a6d822a5e8c807c8d47b4d2dce2 Have a nice day!
comment:3 by , 11 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:5 by , 10 months ago
| Owner: | changed from to |
|---|---|
| Status: | assigned → new |
Reassigning to renodr for security advisories.
comment:6 by , 10 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
Note:
See TracTickets
for help on using tickets.

The patches we need for this are both located in the 2.1.x branch of libcupsfilters: