PT-2026-6329 · Iccdev · Iccdev

Xsscx

·

Published

2026-02-04

·

Updated

2026-02-05

·

CVE-2026-25584

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions iccDEV versions prior to 2.3.1.3
Description iccDEV is a set of libraries and tools for interacting with ICC color management profiles. A stack-buffer-overflow exists in the CIccTagFloatNum<>::GetValues() function when processing a malformed ICC profile. This can lead to an out-of-bounds write on the stack, potentially resulting in memory corruption, information disclosure, or code execution when processing specially crafted ICC files.
Recommendations Update to version 2.3.1.3 or later.

Exploit

Fix

Access of Memory Location After End of Buffer

Memory Corruption

Stack Overflow

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2026-25584
GHSA-XJR3-V3VR-5794

Affected Products

Iccdev