PT-2026-21911 · Iccdev · Iccdev
Sy460129
·
Publicado
2026-02-25
·
Atualizado
2026-02-25
·
CVE-2026-27691
CVSS v3.1
6.2
Média
| Vetor | AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
iccDEV versions prior to 2.3.1.5
Description
iccDEV is a set of libraries and tools for working with ICC color management profiles. A signed integer overflow in the
iccFromCube.cpp file during multiplication can lead to undefined behavior, potentially causing crashes or incorrect ICC profile generation when processing specially crafted or large cube inputs. The issue is addressed by commit 43ae18dd69fc70190d3632a18a3af2f3da1e052a.Recommendations
Update to a version later than 2.3.1.4.
Exploit
Correção
Integer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Iccdev