Buffer Overflow Vulnerability in ICC Color Management Tool by International Color Consortium
CVE-2026-25585
7.8HIGH
What is CVE-2026-25585?
Before version 2.3.1.3, the iccDEV library is susceptible to a buffer overflow due to improper array bounds validation when processing malformed ICC profiles. This vulnerability can allow an attacker to perform out-of-bounds reads, potentially leading to memory disclosure or segmentation faults by accessing data beyond allocated memory boundaries. To mitigate this risk, users are strongly advised to update to version 2.3.1.3 or later.
Affected Version(s)
iccDEV < 2.3.1.3
