Undefined Behavior Vulnerability in iccDEV Libraries by International Color Consortium
CVE-2026-34548

6.2MEDIUM

Key Information:

Status
Vendor
CVE Published:
31 March 2026

What is CVE-2026-34548?

The iccDEV libraries, developed by the International Color Consortium, are susceptible to an Undefined Behavior condition due to an implicit type conversion flaw in its XML conversion tool, specifically in the iccToXml function. This issue arises when a negative signed integer is converted to an unsigned 32-bit integer, altering the intended value and potentially leading to unexpected results. The vulnerability has been resolved in version 2.3.1.6, mitigating the issue for users and ensuring the integrity of color management processes.

Affected Version(s)

iccDEV < 2.3.1.6

References

CVSS V3.1

Score:
6.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.