{"id":"CVE-2026-25502","summary":"iccDEV is vulnerable to stack-buffer-overflow in icFixXml()","details":"iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, stack-based buffer overflow in icFixXml() function when processing malformed ICC profiles, allows potential arbitrary code execution through crafted NamedColor2 tags. This issue has been patched in version 2.3.1.2.","aliases":["GHSA-c2qq-jf7w-rm27"],"modified":"2026-08-12T15:31:53.863358Z","published":"2026-02-03T18:36:36.348Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/25xxx/CVE-2026-25502.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-121","CWE-787"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/25xxx/CVE-2026-25502.json"},{"type":"ADVISORY","url":"https://github.com/InternationalColorConsortium/iccDEV/security/advisories/GHSA-c2qq-jf7w-rm27"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-25502"},{"type":"REPORT","url":"https://github.com/InternationalColorConsortium/iccDEV/issues/537"},{"type":"FIX","url":"https://github.com/InternationalColorConsortium/iccDEV/commit/be5d7ec5cc137c084c08006aee8cd3ed378c7ac2"},{"type":"FIX","url":"https://github.com/InternationalColorConsortium/iccDEV/pull/545"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/internationalcolorconsortium/iccdev","events":[{"introduced":"0"},{"fixed":"ad159eb00bf46fa17496a0f8c4cb49de8918062c"},{"fixed":"be5d7ec5cc137c084c08006aee8cd3ed378c7ac2"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"2.3.1.2"}],"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:color:iccdev:*:*:*:*:*:*:*:*"}}],"versions":["v2.3.1.2","v2.3.1.1","v2.3.1","v2.2.6"],"database_specific":{"vanir_signatures":[{"digest":{"function_hash":"249566190944243138053423510179649554590","length":1298},"id":"CVE-2026-25502-857a7261","signature_type":"Function","signature_version":"v1","source":"https://github.com/internationalcolorconsortium/iccdev/commit/be5d7ec5cc137c084c08006aee8cd3ed378c7ac2","target":{"file":"IccProfLib/IccTagBasic.cpp","function":"CIccTagNamedColor2::Read"},"deprecated":false},{"deprecated":false,"digest":{"line_hashes":["138495038790828891022467959864211522180","39881799369575482285914601801749611606","43768049129128855021666703749570334607","323414557173827842065748924508980803431"],"threshold":0.9},"id":"CVE-2026-25502-f6529d6b","signature_type":"Line","signature_version":"v1","source":"https://github.com/internationalcolorconsortium/iccdev/commit/be5d7ec5cc137c084c08006aee8cd3ed378c7ac2","target":{"file":"IccProfLib/IccTagBasic.cpp"}}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-25502.json","vanir_signatures_modified":"2026-08-12T15:31:53Z"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}