Heap Buffer Overflow in ICC Color Management Library by International Color Consortium
CVE-2026-34539
6.2MEDIUM
What is CVE-2026-34539?
A heap buffer overflow vulnerability exists in the iccDEV libraries that handle ICC color management profiles. Specifically, before version 2.3.1.6, a specially crafted ICC profile coupled with a TIFF input can lead to an out-of-bounds memory access during the TIFF strip writing process. This is seen as an out-of-bounds heap read when utilizing the iccSpecSepToTiff function on a malicious combination of .icc and .tif files, potentially causing application crashes. The issue has been addressed in the latest version.
Affected Version(s)
iccDEV < 2.3.1.6
