CNNVD-202601-1169 Information

CNNVD ID

CNNVD-202601-1169

CVE-2026-21505

  • CNNVD Published: 2026-01-07

Description (Chinese)

iccDEV是International Color Consortium (ICC)开源的一个颜色配置代码库。 iccDEV 2.3.1.2之前版本存在安全漏洞,该漏洞源于无效枚举值导致未定义行为。

Description (English)

iccDEV is an open-source colour configuration code library for International Color Consortium (ICC). iccDEV 2.3.1.2 has a security loophole, which results from invalid numeric values leading to undefined behaviour.

Hazard Level

High

Vulnerability Type

其他

Published

2026-01-07

Last Modified

2026-02-24

References

https://github.com/InternationalColorConsortium/iccDEV/commit/3bbe2088b2796cf0aa4f7fa19f7ccd9ad1c7aba5 https://github.com/InternationalColorConsortium/iccDEV/commit/b1bb72fc3e9442ee1355aabae7314bb7d3fc9d41 https://github.com/InternationalColorConsortium/iccDEV/issues/361 https://github.com/InternationalColorConsortium/iccDEV/pull/419 https://github.com/InternationalColorConsortium/iccDEV/security/advisories/GHSA-j577-8285-qrf9

Patch

https://github.com/InternationalColorConsortium/iccDEV/releases

Share on: