NULL Pointer Dereference in International Color Consortium's IccMAX Library
CVE-2023-46867

6.5MEDIUM

Key Information:

Vendor

Color

Vendor
CVE Published:
30 October 2023

What is CVE-2023-46867?

A null pointer dereference vulnerability exists in the International Color Consortium's IccMAX library, specifically within the CIccXformMatrixTRC::GetCurve function in IccCmm.cpp of libSampleICC.a. This flaw can lead to application crashes and unexpected behavior when processing color transformations. It is crucial for users and developers relying on this library to apply appropriate patches to mitigate potential risks.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.