PT-2026-2086 · Iccdev · Iccdev

Xsscx

·

Published

2026-01-07

·

Updated

2026-01-07

·

CVE-2026-21689

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions iccDEV versions prior to 2.3.1.2
Description iccDEV is a set of libraries and tools for interacting with International Color Consortium (ICC) color management profiles. A Type Confusion issue exists in the CIccProfileXml::ParseBasic() function located in IccXML/IccLibXML/IccProfileXml.cpp. This affects users who process ICC color profiles.
Recommendations Update to version 2.3.1.2 or later.

Exploit

Fix

Improper Check for Exceptional Conditions

Integer Overflow

NULL Pointer Dereference

Type Confusion

RCE

Related Identifiers

CVE-2026-21689
GHSA-5RQC-W93Q-589M

Affected Products

Iccdev