Logic Flaw in IccMAX Could Lead to Unconditional False Returns
CVE-2024-38427
8.8HIGH
Key Information:
- Status
- Vendor
- CVE Published:
- 16 June 2024
What is CVE-2024-38427?
A logic flaw was identified in the International Color Consortium's DemoIccMAX, specifically within the CIccTagXmlProfileSequenceId::ParseXml method in the IccXML framework. This vulnerability leads to an unconditionally false return value, potentially affecting the processing of ICC XML data. Users are encouraged to update to the latest version to mitigate any issues stemming from this flaw.
