Undefined Behavior Vulnerability in iccDEV Libraries by International Color Consortium
CVE-2026-34548
6.2MEDIUM
What is CVE-2026-34548?
The iccDEV libraries, developed by the International Color Consortium, are susceptible to an Undefined Behavior condition due to an implicit type conversion flaw in its XML conversion tool, specifically in the iccToXml function. This issue arises when a negative signed integer is converted to an unsigned 32-bit integer, altering the intended value and potentially leading to unexpected results. The vulnerability has been resolved in version 2.3.1.6, mitigating the issue for users and ensuring the integrity of color management processes.
Affected Version(s)
iccDEV < 2.3.1.6
