Impact
A flaw in the EvaluateProfile method of icStatusCMM::CIccEvalCompare allows a mismatch between expected and actual object types when processing a crafted ICC profile. This type confusion may cause unexpected behavior during profile evaluation. The vulnerability is identified as a classic type confusion and is categorized under CWE-20 and CWE-843.
Affected Systems
International Color Consortium's iccDEV library, any version earlier than 2.3.1.2, is impacted. The issue arises when the library parses ICC color profiles, meaning applications that embed iccDEV to load or manipulate such profiles are susceptible. The affected versions are all releases before the patch included in 2.3.1.2.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, while the EPSS score of less than 1% indicates a low likelihood of exploitation. This vulnerability is not listed in CISA's KEV catalog. The description does not specify the attack vector, but it suggests that an attacker could supply a crafted ICC file to trigger the type confusion. Whether the attack is local or remote is not detailed in the CVE entry.
OpenCVE Enrichment