Buffer Overflow Vulnerability in iccDEV Color Management Tools
CVE-2026-30983
7.8HIGH
What is CVE-2026-30983?
The iccDEV library, used for working with ICC color management profiles, contains a stack buffer overflow vulnerability in the icFixXml() function due to improper use of strcpy(), which can lead to stack memory corruption or crashes in applications utilizing this library. This issue has been addressed in version 2.3.1.5. Users are strongly encouraged to update to this version or later to mitigate potential security risks.
Affected Version(s)
iccDEV < 2.3.1.5
