PT-2026-4545 · Iccdev · Iccdev

Xsscx

·

Published

2026-01-24

·

Updated

2026-01-25

·

CVE-2026-24403

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions iccDEV versions prior to 2.3.1.2
Description iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. In versions 2.3.1.1 and below, an integer overflow exists in the CheckHeader() function within the CIccProfile class when user-controllable input is incorporated into profile data unsafely. Tampering with tag tables, offsets, or size fields can trigger parsing errors, memory corruption, or denial of service, potentially enabling arbitrary code execution or bypassing application logic.
Recommendations Update to version 2.3.1.2 or later.

Exploit

Fix

DoS

Integer Overflow

RCE

Weakness Enumeration

Related Identifiers

CVE-2026-24403
GHSA-PH33-QP8J-5Q34

Affected Products

Iccdev