Heap Buffer Overflow in iccDEV Affecting ICC Color Management Tools
CVE-2026-24405
8.8HIGH
What is CVE-2026-24405?
The iccDEV library, designed for handling ICC color management profiles, is affected by a heap buffer overflow vulnerability in the CIccMpeCalculator::Read() function. This vulnerability arises when user-driven input is improperly included in ICC profile data or structured binary formats, allowing potential attackers to disrupt service operations, manipulate sensitive data, and bypass application logic. This flaw has been remedied in version 2.3.1.2.
Affected Version(s)
iccDEV < 2.3.1.2
