iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, a crafted TIFF input can trigger Undefined Behavior (UB) due to division by zero in the TIFF handling code paths used by iccTiffDump. This issue has been patched in version 2.3.1.6.
References
| Link | Resource |
|---|---|
| https://github.com/InternationalColorConsortium/iccDEV/issues/719 | Exploit Issue Tracking |
| https://github.com/InternationalColorConsortium/iccDEV/pull/723 | Issue Tracking Patch |
| https://github.com/InternationalColorConsortium/iccDEV/security/advisories/GHSA-fxgq-wf5v-25pq | Patch Vendor Advisory |
Configurations
History
17 Jun 2026, 10:39
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/InternationalColorConsortium/iccDEV/issues/719 - Exploit, Issue Tracking |
20 Apr 2026, 14:32
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
|
| First Time |
Color
Color iccdev |
|
| CPE | cpe:2.3:a:color:iccdev:*:*:*:*:*:*:*:* | |
| References | () https://github.com/InternationalColorConsortium/iccDEV/issues/719 - Issue Tracking, Exploit | |
| References | () https://github.com/InternationalColorConsortium/iccDEV/pull/723 - Issue Tracking, Patch | |
| References | () https://github.com/InternationalColorConsortium/iccDEV/security/advisories/GHSA-fxgq-wf5v-25pq - Patch, Vendor Advisory |
31 Mar 2026, 23:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-31 23:17
Updated : 2026-06-17 10:39
NVD link : CVE-2026-34546
Mitre link : CVE-2026-34546
CVE.ORG link : CVE-2026-34546
JSON object : View
Products Affected
color
- iccdev
CWE
CWE-369
Divide By Zero
