Undefined Behavior in ICC Color Management Libraries - iccDEV by International Color Consortium
CVE-2026-34546

6.2MEDIUM

Key Information:

Status
Vendor
CVE Published:
31 March 2026

What is CVE-2026-34546?

A significant issue has been identified in iccDEV's handling of TIFF input, which can lead to undefined behavior due to a division by zero error in the code paths. This vulnerability affects versions prior to 2.3.1.6 and may compromise the stability and security of systems utilizing these libraries for ICC color management profiles. Users are advised to update to version 2.3.1.6 or later to mitigate this issue.

Affected Version(s)

iccDEV < 2.3.1.6

References

CVSS V3.1

Score:
6.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.