CNNVD-202601-1136 Information

CNNVD ID

CNNVD-202601-1136

CVE-2026-21684

  • CNNVD Published: 2026-01-07

Description (Chinese)

iccDEV是International Color Consortium开源的一个颜色配置代码库。 iccDEV 2.3.1.2之前版本存在安全漏洞,该漏洞源于CIccTagSpectralViewingConditions函数存在未定义行为。

Description (English)

iccDEV is a colour configuration code library of the International Color Consortium open source. There is a security loophole in the previous version of iccDEV 2.3.1.2, which stems from the undefined behaviour of the CIccTagSpectralViewingConditions function.

Hazard Level

Medium

Vulnerability Type

其他

Affected Vendor

International Color Consortium

Published

2026-01-07

Last Modified

2026-02-24

References

https://github.com/InternationalColorConsortium/iccDEV/issues/216 https://github.com/InternationalColorConsortium/iccDEV/pull/225 https://github.com/InternationalColorConsortium/iccDEV/security/advisories/GHSA-fg9m-j9x8-8279

Patch

https://github.com/InternationalColorConsortium/iccDEV/releases

Share on: