iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, stack-based buffer overflow in icFixXml() function when processing malformed ICC profiles, allows potential arbitrary code execution through crafted NamedColor2 tags. This issue has been patched in version 2.3.1.2.
History

Tue, 03 Feb 2026 19:00:00 +0000

Type Values Removed Values Added
Description iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, stack-based buffer overflow in icFixXml() function when processing malformed ICC profiles, allows potential arbitrary code execution through crafted NamedColor2 tags. This issue has been patched in version 2.3.1.2.
Title iccDEV is vulnerable to stack-buffer-overflow in icFixXml()
Weaknesses CWE-121
CWE-787
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-02-03T18:36:36.348Z

Reserved: 2026-02-02T18:21:42.485Z

Link: CVE-2026-25502

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-02-03T19:16:26.963

Modified: 2026-02-03T19:16:26.963

Link: CVE-2026-25502

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.