iccDEV has a Heap-based Buffer Overflow in its CIccMBB::Validate() function
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.8epss 0.4%
exploitation probability
0.4%top 66% of all CVEs
observed exploitation
nono source reports it
In short
iccDEV, a tool for color management profiles, has a flaw in how it checks profile data that allows attackers to overflow memory and crash the program or execute malicious code. This affects versions 2.3.1 and earlier.
Technical detail
A heap-based buffer overflow exists in the CIccMBB::Validate() function that processes ICC color profile tag data. An attacker can supply a specially crafted profile file to trigger the overflow during validation, potentially achieving code execution or denial of service. The vulnerability is resolved in version 2.3.1.1.
Summary generated and translated by AI from the official description.
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1 and below have a Heap-based Buffer Overflow in its CIccMBB::Validate function which checks tag data validity. This issue is fixed in version 2.3.1.1.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
InternationalColorConsortium · iccDEV