Undefined Behavior in ICC Color Management Libraries - iccDEV by International Color Consortium
CVE-2026-34546
6.2MEDIUM
What is CVE-2026-34546?
A significant issue has been identified in iccDEV's handling of TIFF input, which can lead to undefined behavior due to a division by zero error in the code paths. This vulnerability affects versions prior to 2.3.1.6 and may compromise the stability and security of systems utilizing these libraries for ICC color management profiles. Users are advised to update to version 2.3.1.6 or later to mitigate this issue.
Affected Version(s)
iccDEV < 2.3.1.6
