iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.3, there is a stack-buffer-overflow vulnerability in CIccTagFloatNum<>::GetValues(). This is triggered when processing a malformed ICC profile. The vulnerability allows an out-of-bounds write on the stack, potentially leading to memory corruption, information disclosure, or code execution when processing specially crafted ICC files. This issue has been patched in version 2.3.1.3.
History

Wed, 04 Feb 2026 22:15:00 +0000

Type Values Removed Values Added
Description iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.3, there is a stack-buffer-overflow vulnerability in CIccTagFloatNum<>::GetValues(). This is triggered when processing a malformed ICC profile. The vulnerability allows an out-of-bounds write on the stack, potentially leading to memory corruption, information disclosure, or code execution when processing specially crafted ICC files. This issue has been patched in version 2.3.1.3.
Title iccDEV vulnerable to Stack-based Buffer Overflow in CIccTagFloatNum::GetValues()
Weaknesses CWE-119
CWE-121
CWE-787
CWE-788
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-02-04T22:11:10.830Z

Reserved: 2026-02-03T01:02:46.715Z

Link: CVE-2026-25584

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-02-04T22:16:01.683

Modified: 2026-02-04T22:16:01.683

Link: CVE-2026-25584

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.