Heap Out-of-Bounds Read in ICC Color Management Tool by International Color Consortium
CVE-2026-31797

6.1MEDIUM

Key Information:

Status
Vendor
CVE Published:
10 March 2026

What is CVE-2026-31797?

A vulnerability exists in the iccDEV libraries that manage ICC color profiles. Before version 2.3.1.5, the CTiffImg::ReadLine() function may trigger a heap out-of-bounds read when processing specially crafted TIFF images within the iccApplyProfiles. This could result in memory disclosure or cause the application to crash, affecting stability and security. The issue has been addressed and patched in version 2.3.1.5.

Affected Version(s)

iccDEV < 2.3.1.5

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.