PT-2026-6296 · Iccdev · Iccdev

Xsscx

·

Published

2026-02-03

·

Updated

2026-02-10

·

CVE-2026-25502

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions iccDEV versions prior to 2.3.1.2
Description iccDEV is a set of libraries and tools for interacting with ICC color management profiles. A stack-based buffer overflow exists in the icFixXml() function when processing malformed ICC profiles. This flaw, triggered by crafted NamedColor2 tags, could allow for arbitrary code execution.
Recommendations Update to version 2.3.1.2 or later.

Exploit

Fix

Stack Overflow

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2026-25502
GHSA-C2QQ-JF7W-RM27

Affected Products

Iccdev