Undefined Behavior in ICC Color Management Profiles in iccDEV Library
CVE-2026-34547

6.2MEDIUM

Key Information:

Status
Vendor
CVE Published:
31 March 2026

What is CVE-2026-34547?

The iccDEV library, designed for ICC color management profiles, contains a vulnerability that can be triggered by a specially crafted ICC profile when executing the iccDumpProfile function. This flaw, which exists in versions prior to 2.3.1.6, results inUndefined Behavior that could potentially be exploited. Users are strongly urged to update to the patched version to mitigate any security risks associated with this vulnerability.

Affected Version(s)

iccDEV < 2.3.1.6

References

CVSS V3.1

Score:
6.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.