Heap Buffer Overflow Vulnerability in iccDEV Libraries by International Color Consortium
CVE-2026-34534
6.2MEDIUM
What is CVE-2026-34534?
A vulnerability in iccDEV, a library for handling ICC color management profiles, allows for a heap buffer overflow due to a crafted ICC profile. This issue manifests in the CIccMpeSpectralMatrix::Describe() function, leading to an out-of-bounds heap read when using iccDumpProfile on a malicious profile. This vulnerability was addressed in version 2.3.1.6, which mitigates the associated risks.
Affected Version(s)
iccDEV < 2.3.1.6
