Heap Buffer Overflow Vulnerability in iccDEV Libraries from International Color Consortium
CVE-2026-25583
7.8HIGH
What is CVE-2026-25583?
A heap buffer overflow vulnerability exists in the iccDEV library's CIccFileIO::Read8() function, which handles the reading of ICC profile files. This vulnerability arises from the processing of malformed ICC profile files through an unchecked fread operation, potentially allowing attackers to exploit this flaw to execute arbitrary code. The issue has been addressed in version 2.3.1.3, offering a patch that mitigates the risk associated with this security weakness.
Affected Version(s)
iccDEV < 2.3.1.3
