Heap Buffer Overflow in iccDEV Libraries for ICC Color Management Profiles
CVE-2026-34556
6.2MEDIUM
What is CVE-2026-34556?
The iccDEV library, a toolset designed for ICC color management profiles, contains a heap buffer overflow vulnerability in the icAnsiToUtf8() function within the XML conversion process. This flaw arises when a specially crafted ICC profile is processed, leading the function to misinterpret an input buffer as a null-terminated C-string. This results in out-of-bounds memory access, specifically an attempt to read beyond the allocated heap space, potentially causing system instability or exploitation opportunities. Users are encouraged to upgrade to version 2.3.1.6 or later to mitigate this issue.
Affected Version(s)
iccDEV < 2.3.1.6
