A vulnerability categorized as critical has been discovered in InternationalColorConsortium iccDEV 2.3.1.1/2.3.1.2/2.3.1.3/2.3.1.4/2.3.1.5. This impacts the function CTiffImg::WriteLine of the component ICC Color Profile Handler. Such manipulation leads to heap-based buffer overflow. The attack can be launched remotely.
| Vendor | Product | Versions |
|---|---|---|
| internationalcolorconsortium | iccdev | < 2.3.1.6, 2.3.1.1, 2.3.1.2, 2.3.1.3, 2.3.1.4, 2.3.1.5 |
Updated severity to CRITICAL, added affected versions 2.3.1.1 to 2.3.1.5, and noted that the vulnerability is actively exploited.
Initial creation