Undefined Behavior Vulnerability in iccDEV Libraries by International Color Consortium
CVE-2026-24411
7.1HIGH
What is CVE-2026-24411?
The iccDEV library, designed for interacting with ICC color management profiles, has a vulnerability in versions 2.3.1.1 and earlier that allows for undefined behavior due to unsafe incorporation of user-controlled input into ICC profile data. This flaw can potentially lead to Denial of Service (DoS), data manipulation, and bypassing application logic. It is essential to upgrade to version 2.3.1.2 or later to mitigate these risks.
Affected Version(s)
iccDEV < 2.3.1.2
