


Perceptive Security
SOC/SIEM Consultancy

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is a stack buffer overflow in CIccTagNum<>:…
Published:
9 maart 2026 om 23:00:00
Alert date:
10 maart 2026 om 19:06:17
Source:
nvd.nist.gov
Supply Chain & Dependencies
iccDEV, a library and toolset for working with ICC color management profiles, contains a stack buffer overflow vulnerability in the CIccTagNum<>::GetValues() function. The vulnerability affects versions prior to 2.3.1.5 and can cause stack memory corruption or application crashes. The issue has been resolved in version 2.3.1.5. This vulnerability could potentially be exploited to cause denial of service or potentially execute arbitrary code through stack corruption.
Technical details
Mitigation steps:
Affected products:
iccDEV
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-30987
https://github.com/InternationalColorConsortium/iccDEV/issues/618
https://github.com/InternationalColorConsortium/iccDEV/pull/638
https://github.com/InternationalColorConsortium/iccDEV/releases/tag/v2.3.1.5
https://github.com/InternationalColorConsortium/iccDEV/security/advisories/GHSA-fj57-gfhq-rjqr
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
