Buffer Overflow Vulnerability in ICC Color Management Tool by International Color Consortium
CVE-2026-25585

7.8HIGH

Key Information:

Status
Vendor
CVE Published:
4 February 2026

What is CVE-2026-25585?

Before version 2.3.1.3, the iccDEV library is susceptible to a buffer overflow due to improper array bounds validation when processing malformed ICC profiles. This vulnerability can allow an attacker to perform out-of-bounds reads, potentially leading to memory disclosure or segmentation faults by accessing data beyond allocated memory boundaries. To mitigate this risk, users are strongly advised to update to version 2.3.1.3 or later.

Affected Version(s)

iccDEV < 2.3.1.3

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.