CVE-2026-25503: fallo de gravedad alta en InternationalColorConsortium iccDEV
iccDEV Has Type Confusion in CIccTagEmbeddedHeightImage::Validate()
Publicada el · Actualizada el
21Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 7.1epss 0.5%
probabilidad de explotación
0.5%top 58% de las CVE
explotación observada
noninguna fuente lo reporta
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, type confusion allowed malformed ICC profiles to trigger undefined behavior when loading invalid icImageEncodingType values causing denial of service. This issue has been patched in version 2.3.1.2.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H
Productos afectados
InternationalColorConsortium · iccDEVCVEs relacionadas — InternationalColorConsortium iccDEV
En el mismo producto, de las más peligrosas a las menos.
CVE-2026-22861HIGHiccDEV has a heap-buffer-overflow in SIccCalcOp::Describe() at IccProfLib/IccMpeCalc.cppEPSS 0.7%CVE-2026-24412HIGHiccDEV has Heap Buffer Overflow in icCurvesFromXml()EPSS 0.6%CVE-2026-24406HIGHiccDEV has Heap Buffer Overflow in CIccTagNamedColor2::SetSize()EPSS 0.6%CVE-2026-24405HIGHiccDEV has Heap Buffer Overflow in CIccMpeCalculator::Read()EPSS 0.6%CVE-2026-24407HIGHiccDEV has Undefined Behavior in icSigCalcOp()EPSS 0.5%CVE-2026-24404HIGHiccDEV has Null Pointer Deference and Undefined Behavior in CIccXmlArrayType()EPSS 0.5%
Referencias
https://github.com/InternationalColorConsortium/iccDEV/commit/353e6517a31cb6ac9fdd44ac0103bc2fadb25175https://github.com/InternationalColorConsortium/iccDEV/issues/539https://github.com/InternationalColorConsortium/iccDEV/pull/547https://github.com/InternationalColorConsortium/iccDEV/security/advisories/GHSA-pf84-4c7q-x764