Heap Buffer Overflow in iccDEV Libraries for ICC Color Management Profiles
CVE-2026-34556

6.2MEDIUM

Key Information:

Status
Vendor
CVE Published:
31 March 2026

What is CVE-2026-34556?

The iccDEV library, a toolset designed for ICC color management profiles, contains a heap buffer overflow vulnerability in the icAnsiToUtf8() function within the XML conversion process. This flaw arises when a specially crafted ICC profile is processed, leading the function to misinterpret an input buffer as a null-terminated C-string. This results in out-of-bounds memory access, specifically an attempt to read beyond the allocated heap space, potentially causing system instability or exploitation opportunities. Users are encouraged to upgrade to version 2.3.1.6 or later to mitigate this issue.

Affected Version(s)

iccDEV < 2.3.1.6

References

CVSS V3.1

Score:
6.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.