Stack-Based Buffer Overflow in DemoIccMAX by International Color Consortium
CVE-2023-46602

8.8HIGH

Key Information:

Vendor

Color

Vendor
CVE Published:
23 October 2023

What is CVE-2023-46602?

In the DemoIccMAX library by the International Color Consortium, a stack-based buffer overflow exists in the icFixXml function found in IccXML/IccLibXML/IccUtilXml.cpp. This security flaw can be exploited to potentially allow unauthorized access or manipulation of data within applications utilizing this library.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.