Executive brief
iccDEV is a library for reading and manipulating ICC color management profiles, which are used in image processing and color-critical applications. A flaw in how the library parses embedded color profiles can cause it to reject or crash when processing certain valid ICC profile files, disrupting workflows that depend on color management.
Technical details
A size_t underflow vulnerability exists in the CIccEmbedIO::Read8() function when parsing ICC profiles containing icSigEmbeddedV5ProfileTag data with icSigEmbeddedProfileType payloads. The vulnerable code incorrectly handles the size calculation for embedded profile reads, leading to an integer underflow condition. An attacker can craft a malicious ICC profile file that, when opened by an application using iccDEV, triggers the underflow and causes the parser to fail or potentially crash. The vulnerability affects all versions prior to 2.3.2.1, which includes the patch. No authentication or special privileges are required; the attack requires only that a user open a crafted ICC profile file.
Affected products
- International Color Consortium iccDEV prior to 2.3.2.1
Timeline
- 2026-08-21: disclosed
- 2026-05-28: patched: Fix committed in PR #1201 on 2026-05-28; version 2.3.2.1 patches the issue