← back

iccDEV Undefined Behavior (UB) and Out of Memory in CIccProfile::LoadTag()

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 8.8epss 0.4%
exploitation probability
0.4%top 70% of all CVEs
observed exploitation
nono source reports it
In short

iccDEV color profile library versions 2.3.1.1 and earlier have memory handling bugs that can cause crashes or unpredictable behavior when processing malformed ICC profile files. These flaws could be exploited by attackers distributing specially crafted color profile files.

Technical detail

CIccProfile::LoadTag() in iccDEV ≤2.3.1.1 contains out-of-bounds read conditions (CWE-125) and integer overflow vulnerabilities (CWE-190) leading to undefined behavior and memory exhaustion. Attack vector involves supplying maliciously crafted ICC profile files; no authentication required. Impact includes denial of service and potential information disclosure.

Summary generated and translated by AI from the official description.
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below are prone to have Undefined Behavior (UB) and Out of Memory errors. This issue is fixed in version 2.3.1.2.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H