top of page
perceptive_background_267k.jpg

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is a stack buffer overflow in icFixXml() (s…

Published:

9 March 2026 at 23:00:00

Alert date:

10 March 2026 at 19:06:17

Source:

nvd.nist.gov

Click to open the original link from this advisory

Supply Chain & Dependencies

iccDEV, a library and toolset for ICC color management profiles, contains a stack buffer overflow vulnerability in the icFixXml() function. The vulnerability stems from unsafe use of strcpy() which can cause stack memory corruption or application crashes. The issue affects versions prior to 2.3.1.5 and has been patched in version 2.3.1.5. This buffer overflow could potentially be exploited by attackers to achieve code execution or cause denial of service conditions.

Technical details

Mitigation steps:

Affected products:

iccDEV

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page