Stack-Based Buffer Overflow Vulnerability in iccDEV Color Management Tools
CVE-2026-25502

7.8HIGH

Key Information:

Status
Vendor
CVE Published:
3 February 2026

What is CVE-2026-25502?

The iccDEV library suite, which enables the management and manipulation of ICC color profiles, is subject to a stack-based buffer overflow within the icFixXml() function. This vulnerability arises when the software processes malformed ICC profiles, specifically through the use of crafted NamedColor2 tags. Such exploitation may lead to delayed execution of arbitrary code. The issue was resolved in iccDEV version 2.3.1.2, making it essential for users to update to this version to mitigate security risks.

Affected Version(s)

iccDEV < 2.3.1.2

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.