Logic Flaw in IccMAX Could Lead to Unconditional False Returns
CVE-2024-38427

8.8HIGH

Key Information:

Vendor
CVE Published:
16 June 2024

What is CVE-2024-38427?

A logic flaw was identified in the International Color Consortium's DemoIccMAX, specifically within the CIccTagXmlProfileSequenceId::ParseXml method in the IccXML framework. This vulnerability leads to an unconditionally false return value, potentially affecting the processing of ICC XML data. Users are encouraged to update to the latest version to mitigate any issues stemming from this flaw.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.