Impact
iccDEV is a library that handles ICC color profiles. In releases before 2.3.1.2, the CIccTagXmlTagData::ToXml() function has a type‑confusion flaw that can be triggered by supplying a crafted XML tag inside a profile. The incorrect handling of data types may lead to memory corruption, corrupted profile data, or other unintended behavior. The description of the vulnerability does not indicate that code execution is possible, only that the library misinterprets input data.
Affected Systems
All versions of the International Color Consortium’s iccDEV library older than 2.3.1.2 that are used to read or process ICC color profiles are affected. Applications, services, or third‑party components that embed or link against the vulnerable library are at risk when they import data from untrusted profiles.
Risk and Exploitability
The CVSS score of 6.3 reflects moderate severity, while the EPSS score of less than 1% indicates that exploitation attempts are expected to be rare. It is not listed in the CISA KEV catalog. The likely attack vector is file‑based: an attacker supplies a malicious ICC profile that is processed by the vulnerable library. If the profile is interpreted in a privileged or sensitive context, untrusted data could corrupt application state or compromise data integrity.
OpenCVE Enrichment