iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, there is an Undefined Behavior (UB) condition in the XML conversion tooling path (iccToXml) caused by an implicit conversion from a negative signed integer to icUInt32Number (unsigned 32-bit), which changes the value. This issue has been patched in version 2.3.1.6.
Metrics
Affected Vendors & Products
References
History
Mon, 20 Apr 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Color
Color iccdev |
|
| CPEs | cpe:2.3:a:color:iccdev:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Color
Color iccdev |
Thu, 02 Apr 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Internationalcolorconsortium
Internationalcolorconsortium iccdev |
|
| Vendors & Products |
Internationalcolorconsortium
Internationalcolorconsortium iccdev |
Wed, 01 Apr 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 01 Apr 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, there is an Undefined Behavior (UB) condition in the XML conversion tooling path (iccToXml) caused by an implicit conversion from a negative signed integer to icUInt32Number (unsigned 32-bit), which changes the value. This issue has been patched in version 2.3.1.6. | |
| Title | iccDEV: UB at IccUtilXml.cpp | |
| Weaknesses | CWE-681 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-03-31T22:09:49.333Z
Updated: 2026-04-01T19:00:50.308Z
Reserved: 2026-03-30T16:31:39.264Z
Link: CVE-2026-34548
Updated: 2026-04-01T19:00:46.779Z
Status : Analyzed
Published: 2026-03-31T23:17:09.607
Modified: 2026-04-20T14:32:53.423
Link: CVE-2026-34548
No data.
ReportizFlow