Heap-based Buffer Overflow Vulnerability in ICC Color Management Library by iccDEV
CVE-2026-30979

7.8HIGH

Key Information:

Status
Vendor
CVE Published:
10 March 2026

What is CVE-2026-30979?

The ICC Color Management Library by iccDEV contains a heap-based buffer overflow vulnerability in the CIccCalculatorFunc::InitSelectOp() function. This vulnerability can be exploited through local user interactions, leading to memory corruption and potential crashes of applications utilizing the affected library. The issue has been addressed in version 2.3.1.5, emphasizing the importance for users to update their installations to ensure security and stability.

Affected Version(s)

iccDEV < 2.3.1.5

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.