{"id":"CVE-2026-21495","summary":"Division by Zero in iccDEV TIFF Image Reader","details":"iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, iccDEV is vulnerable to division by zero in the TIFF Image Reader. This issue has been patched in version 2.3.1.2.","aliases":["GHSA-xhrm-79rg-5784"],"modified":"2026-08-12T15:32:50.062061Z","published":"2026-01-07T17:08:46.342Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-20","CWE-369"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/21xxx/CVE-2026-21495.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/21xxx/CVE-2026-21495.json"},{"type":"ADVISORY","url":"https://github.com/InternationalColorConsortium/iccDEV/security/advisories/GHSA-xhrm-79rg-5784"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-21495"},{"type":"FIX","url":"https://github.com/InternationalColorConsortium/iccDEV/commit/10c34179a0332a869c2b46e305a9cd23a6311dfe"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/internationalcolorconsortium/iccdev","events":[{"introduced":"0"},{"fixed":"ad159eb00bf46fa17496a0f8c4cb49de8918062c"},{"fixed":"10c34179a0332a869c2b46e305a9cd23a6311dfe"}],"database_specific":{"cpe":"cpe:2.3:a:color:iccdev:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"2.3.1.2"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v2.3.1.1","v2.3.1","v2.2.6"],"database_specific":{"vanir_signatures_modified":"2026-08-12T15:32:50Z","vanir_signatures":[{"signature_version":"v1","source":"https://github.com/internationalcolorconsortium/iccdev/commit/10c34179a0332a869c2b46e305a9cd23a6311dfe","target":{"file":"Tools/CmdLine/IccApplyProfiles/TiffImg.cpp"},"deprecated":false,"digest":{"line_hashes":["276443516231419981396139560051727666118","193551717623325844917682083705432735161","192876210739766605709373257974080405413","23535979757052397183212540178970079993","190413770042934778773930699680313857967","211912942786337229480765267609083903659","93571976472041413848853972030248631152","173232471236608145211416124277291692751","206955025824983011610394515182564445552","156832136395203541270912877188117789353","205530024965244746737165629090781029714","274825887259886909331437273031391040504"],"threshold":0.9},"id":"CVE-2026-21495-52a1345d","signature_type":"Line"},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/internationalcolorconsortium/iccdev/commit/10c34179a0332a869c2b46e305a9cd23a6311dfe","target":{"file":"Tools/CmdLine/IccApplyProfiles/TiffImg.cpp","function":"CTiffImg::Open"},"deprecated":false,"digest":{"function_hash":"231489380924635773853488565580210105768","length":2066},"id":"CVE-2026-21495-6685b018"},{"deprecated":false,"digest":{"function_hash":"77237337938600900552586182339464950755","length":1169},"id":"CVE-2026-21495-693768c4","signature_type":"Function","signature_version":"v1","source":"https://github.com/internationalcolorconsortium/iccdev/commit/10c34179a0332a869c2b46e305a9cd23a6311dfe","target":{"file":"Tools/CmdLine/IccApplyProfiles/TiffImg.cpp","function":"CTiffImg::ReadLine"}}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-21495.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"}]}