Stack Buffer Overflow in iccDEV Color Management Library
CVE-2026-34542

6.2MEDIUM

Key Information:

Status
Vendor
CVE Published:
31 March 2026

What is CVE-2026-34542?

The iccDEV color management library contains a vulnerability that allows a crafted ICC profile to result in a stack buffer overflow when processed through the CIccCalculatorFunc::Apply() function via iccApplyNamedCmm. This vulnerability has been documented to trigger a memory safety issue that is specifically triggered during MPE calculator and curve set initialization. The flaw was discovered and addressed in version 2.3.1.6, which mitigates the risks associated with this exposure. Users are strongly advised to upgrade to the latest version to safeguard against potential exploits.

Affected Version(s)

iccDEV < 2.3.1.6

References

CVSS V3.1

Score:
6.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.