iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, a crafted TIFF input can trigger Undefined Behavior (UB) due to division by zero in the TIFF handling code paths used by iccTiffDump. This issue has been patched in version 2.3.1.6.
References
| Link | Resource |
|---|---|
| https://github.com/InternationalColorConsortium/iccDEV/issues/719 | Issue Tracking Exploit |
| https://github.com/InternationalColorConsortium/iccDEV/pull/723 | Issue Tracking Patch |
| https://github.com/InternationalColorConsortium/iccDEV/security/advisories/GHSA-fxgq-wf5v-25pq | Patch Vendor Advisory |
Configurations
History
20 Apr 2026, 14:32
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/InternationalColorConsortium/iccDEV/issues/719 - Issue Tracking, Exploit | |
| References | () https://github.com/InternationalColorConsortium/iccDEV/pull/723 - Issue Tracking, Patch | |
| References | () https://github.com/InternationalColorConsortium/iccDEV/security/advisories/GHSA-fxgq-wf5v-25pq - Patch, Vendor Advisory | |
| Summary |
|
|
| First Time |
Color
Color iccdev |
|
| CPE | cpe:2.3:a:color:iccdev:*:*:*:*:*:*:*:* |
31 Mar 2026, 23:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-31 23:17
Updated : 2026-04-20 14:32
NVD link : CVE-2026-34546
Mitre link : CVE-2026-34546
CVE.ORG link : CVE-2026-34546
JSON object : View
Products Affected
color
- iccdev
CWE
CWE-369
Divide By Zero
