Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 20 Apr 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Color
Color iccdev |
|
| CPEs | cpe:2.3:a:color:iccdev:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Color
Color iccdev |
Thu, 02 Apr 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Internationalcolorconsortium
Internationalcolorconsortium iccdev |
|
| Vendors & Products |
Internationalcolorconsortium
Internationalcolorconsortium iccdev |
Wed, 01 Apr 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, a crafted ICC profile can trigger a heap-buffer-overflow (HBO) in CIccMpeSpectralMatrix::Describe(). The issue is observable under AddressSanitizer as an out-of-bounds heap read when running iccDumpProfile on a malicious profile. This issue has been patched in version 2.3.1.6. | |
| Title | iccDEV: HBO in CIccMpeSpectralMatrix::Describe() | |
| Weaknesses | CWE-122 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-01T15:52:51.235Z
Reserved: 2026-03-30T16:03:31.048Z
Link: CVE-2026-34534
No data.
Status : Analyzed
Published: 2026-03-31T22:16:20.803
Modified: 2026-04-20T13:41:01.593
Link: CVE-2026-34534
No data.
OpenCVE Enrichment
Updated: 2026-04-02T20:10:19Z