Impact
The vulnerability is a type confusion flaw in the CIccTag:IsTypeCompressed() function of the iccDEV library. It can result in memory corruption or improper handling of ICC color profiles, potentially leading to application crashes or unspecified behavior. The weakness is categorized as type confusion and related to invalid type checks.
Affected Systems
The affected vendor is International Color Consortium, software product iccDEV. All releases before version 2.3.1.2 are vulnerable. No other vendors or product families are listed.
Risk and Exploitability
The CVSS score is 5.4, indicating moderate severity, while the EPSS score is less than 1%, suggesting a low likelihood of exploitation. The vulnerability is not listed in CISA's KEV catalog, and no workarounds are available. Attackers could potentially exploit the flaw by providing a crafted ICC profile to a system that consumes the vulnerable library, which could trigger type confusion and possibly lead to memory corruption.
OpenCVE Enrichment