iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below are vulnerable to Out-of-bounds Read, Heap-based Buffer Overflow and Improper Null Termination through its CIccTagText::Read function. This issue is fixed in version 2.3.1.2.
References
Configurations
History
14 Jan 2026, 18:45
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Color
Color iccdev |
|
| CPE | cpe:2.3:a:color:iccdev:*:*:*:*:*:*:*:* | |
| References | () https://github.com/InternationalColorConsortium/iccDEV/commit/9daaccceb231c43db8cab312ee5bbe9d2aa6b153 - Patch | |
| References | () https://github.com/InternationalColorConsortium/iccDEV/security/advisories/GHSA-4j2g-rvv4-86vg - Vendor Advisory |
06 Jan 2026, 14:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-06 14:15
Updated : 2026-01-14 18:45
NVD link : CVE-2026-21488
Mitre link : CVE-2026-21488
CVE.ORG link : CVE-2026-21488
JSON object : View
Products Affected
color
- iccdev
