CVE-2025-64524
Last modified
CVE-2025-64524 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. cups-filters contains backends, filters, and other software required to get the cups printing service working on operating systems other than macos. In versions 2.0.1 and prior, a heap-buffer-overflow vulnerability in the rastertopclx filter causes the program to crash with a segmentation fault when processing maliciously crafted input data. EPSS estimates a 0.18% chance of exploitation in the next 30 days.
Description
cups-filters contains backends, filters, and other software required to get the cups printing service working on operating systems other than macos. In versions 2.0.1 and prior, a heap-buffer-overflow vulnerability in the rastertopclx filter causes the program to crash with a segmentation fault when processing maliciously crafted input data. This issue can be exploited to trigger memory corruption, potentially leading to arbitrary code execution. This issue has been patched via commit 956283c.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Openprinting | Cups-Filters | <= 2.0.1 |
References
- https://github.com/OpenPrinting/cups-filters/security/advisories/GHSA-rq44-2q5p-x3hvExploit, Vendor Advisory
- http://www.openwall.com/lists/oss-security/2025/11/20/1Mailing List, Patch
- https://github.com/OpenPrinting/cups-filters/security/advisories/GHSA-rq44-2q5p-x3hvExploit, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-64524?
How severe is CVE-2025-64524?
How do I fix CVE-2025-64524?
Are you affected by CVE-2025-64524?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
