iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, a crafted TIFF input can trigger Undefined Behavior (UB) due to division by zero in the TIFF handling code paths used by iccTiffDump. This issue has been patched in version 2.3.1.6.
| Vendor | Product | Versions |
|---|---|---|
| internationalcolorconsortium | iccdev | < 2.3.1.6, 2.3.1.1, 2.3.1.2, 2.3.1.3, 2.3.1.4, 2.3.1.5 |
Updated affected versions to include 2.3.1.1 through 2.3.1.5, changed severity to HIGH, and noted that no exploit is available.
Initial creation