iccDEV provides a set of libraries and tools for working with ICC color management profiles. In versions up to and including 2.3.1.4, heap-buffer-overflow read occurs during CIccTagTextDescription::Release() when strlen() reads past a heap buffer while parsing ICC profile XML text description tags, causing a crash. Commit 29d088840b962a7cdd35993dfabc2cb35a049847 fixes the issue. No known workarounds are available.
Metrics
Affected Vendors & Products
References
History
Wed, 25 Feb 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | iccDEV provides a set of libraries and tools for working with ICC color management profiles. In versions up to and including 2.3.1.4, heap-buffer-overflow read occurs during CIccTagTextDescription::Release() when strlen() reads past a heap buffer while parsing ICC profile XML text description tags, causing a crash. Commit 29d088840b962a7cdd35993dfabc2cb35a049847 fixes the issue. No known workarounds are available. | |
| Title | iccDEV has HBO in CIccTagTextDescription::Release() | |
| Weaknesses | CWE-125 CWE-170 CWE-787 |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-02-25T20:42:56.820Z
Reserved: 2026-02-23T17:56:51.202Z
Link: CVE-2026-27692
No data.
Status : Awaiting Analysis
Published: 2026-02-25T15:20:52.727
Modified: 2026-02-25T15:22:44.317
Link: CVE-2026-27692
No data.
OpenCVE Enrichment
No data.