Heap Out-of-Bounds Read in ICC Color Management Tool by International Color Consortium
CVE-2026-31797
6.1MEDIUM
What is CVE-2026-31797?
A vulnerability exists in the iccDEV libraries that manage ICC color profiles. Before version 2.3.1.5, the CTiffImg::ReadLine() function may trigger a heap out-of-bounds read when processing specially crafted TIFF images within the iccApplyProfiles. This could result in memory disclosure or cause the application to crash, affecting stability and security. The issue has been addressed and patched in version 2.3.1.5.
Affected Version(s)
iccDEV < 2.3.1.5
