Null-Pointer Dereference Vulnerability in iccDEV Libraries
CVE-2026-34551
6.2MEDIUM
What is CVE-2026-34551?
The iccDEV library, utilized for handling ICC color management profiles, experienced a Null-Pointer Dereference vulnerability in its CIccTagLut16::Write() function. This flaw can be exploited when processing specially crafted ICC profiles embedded within TIFF files, potentially leading to unexpected behavior or crashes during execution. It is recommended that users upgrade to version 2.3.1.6 or later to mitigate this risk. For further details, refer to the security advisory.
Affected Version(s)
iccDEV < 2.3.1.6
