Out-of-Bounds Read Vulnerability in International Color Consortium DemoIccMAX
CVE-2023-48736

6.5MEDIUM

Key Information:

Vendor

Color

Vendor
CVE Published:
18 November 2023

What is CVE-2023-48736?

A vulnerability in the International Color Consortium's DemoIccMAX, specifically in the CIccCLUT::Interp2d function within IccTagLut.cpp of libSampleICC.a, allows for out-of-bounds read conditions. This can potentially lead to unintended data exposure or application behavior. It is crucial for users of affected versions to review the security implications and apply necessary updates. Further details can be found in the GitHub pull request addressing this issue.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.