PT-2026-21911 · Iccdev · Iccdev

Sy460129

·

Publicado

2026-02-25

·

Atualizado

2026-02-25

·

CVE-2026-27691

CVSS v3.1

6.2

Média

VetorAV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions iccDEV versions prior to 2.3.1.5
Description iccDEV is a set of libraries and tools for working with ICC color management profiles. A signed integer overflow in the iccFromCube.cpp file during multiplication can lead to undefined behavior, potentially causing crashes or incorrect ICC profile generation when processing specially crafted or large cube inputs. The issue is addressed by commit 43ae18dd69fc70190d3632a18a3af2f3da1e052a.
Recommendations Update to a version later than 2.3.1.4.

Exploit

Correção

Integer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-27691
GHSA-4GFJ-4CJH-53V5

Produtos afetados

Iccdev