Heap Buffer Overflow in ICC Color Management Tool by International Color Consortium
CVE-2026-34554
6.2MEDIUM
What is CVE-2026-34554?
A vulnerability in the ICC color management tool, iccDEV, allows a heap buffer overflow through malformed JSON input in the iccApplySearch utility. This issue, found in versions prior to 2.3.1.6, can cause out-of-bounds memory access. When the costFunc function is invoked with specially crafted configurations, it can lead to potential exploit scenarios, making it critical for users to update to the latest version to mitigate risks.
Affected Version(s)
iccDEV < 2.3.1.6
