{"id":"CVE-2026-21673","summary":"iccDEV has Integer Overflow/Underflow in CIccXmlArrayType::ParseTextCountNum()","details":"iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1 and below have overflows and underflows in  CIccXmlArrayType::ParseTextCountNum(). This vulnerability affects users of the iccDEV library who process ICC color profiles. This issue is fixed in version 2.3.1.1.","aliases":["GHSA-g66g-f82c-vgm6"],"modified":"2026-08-12T15:31:32.879401Z","published":"2026-01-06T01:32:21.632Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-190","CWE-681","CWE-704"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/21xxx/CVE-2026-21673.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/21xxx/CVE-2026-21673.json"},{"type":"ADVISORY","url":"https://github.com/InternationalColorConsortium/iccDEV/security/advisories/GHSA-g66g-f82c-vgm6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-21673"},{"type":"REPORT","url":"https://github.com/InternationalColorConsortium/iccDEV/issues/243"},{"type":"FIX","url":"https://github.com/InternationalColorConsortium/iccDEV/commit/32740802ee14418bd14c429d7e2f142d92cd5c4f"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/internationalcolorconsortium/iccdev","events":[{"introduced":"0"},{"fixed":"e9b21d2294add231d3a21698e303ddb2e569dc00"},{"fixed":"32740802ee14418bd14c429d7e2f142d92cd5c4f"}],"database_specific":{"cpe":"cpe:2.3:a:color:iccdev:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"2.3.1.1"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v2.3.1","v2.2.6"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-21673.json","vanir_signatures_modified":"2026-08-12T15:31:32Z","vanir_signatures":[{"signature_type":"Function","signature_version":"v1","source":"https://github.com/internationalcolorconsortium/iccdev/commit/32740802ee14418bd14c429d7e2f142d92cd5c4f","target":{"file":"IccXML/IccLibXML/IccUtilXml.cpp","function":"ParseText"},"deprecated":false,"digest":{"function_hash":"152454494106800250354010900542365286216","length":816},"id":"CVE-2026-21673-61055091"},{"id":"CVE-2026-21673-ca009a7d","signature_type":"Line","signature_version":"v1","source":"https://github.com/internationalcolorconsortium/iccdev/commit/32740802ee14418bd14c429d7e2f142d92cd5c4f","target":{"file":"IccXML/IccLibXML/IccUtilXml.cpp"},"deprecated":false,"digest":{"line_hashes":["179363570527685760522742127448130688610","333973454931073845595064369183628243959","18266994994392353777589489190576287271","118808003486973557659731256513565950317","338245875221859356371192051477805599978","235195950957324671338302587606926210443","116230471929830415496207546872226788596","334005829666856690910734464239611666542","241290352615898775904793048636694544316","326301098923645085203906581424654045809","89055519609512366450595748040060491645","334005829666856690910734464239611666542","241290352615898775904793048636694544316","326301098923645085203906581424654045809","99951254588498072073449637824948825232"],"threshold":0.9}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}