Stack-Based Buffer Overflow Vulnerability in iccDEV Color Management Tools
CVE-2026-25502
7.8HIGH
What is CVE-2026-25502?
The iccDEV library suite, which enables the management and manipulation of ICC color profiles, is subject to a stack-based buffer overflow within the icFixXml() function. This vulnerability arises when the software processes malformed ICC profiles, specifically through the use of crafted NamedColor2 tags. Such exploitation may lead to delayed execution of arbitrary code. The issue was resolved in iccDEV version 2.3.1.2, making it essential for users to update to this version to mitigate security risks.
Affected Version(s)
iccDEV < 2.3.1.2
