Description
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below are vulnerable to Type Confusion in its CIccSingleSampledeCurveXml class during XML Curve Serialization. This issue is fixed in version 2.3.1.2.
Problem types
CWE-188: Reliance on Data/Memory Layout
CWE-703: Improper Check or Handling of Exceptional Conditions
CWE-843: Access of Resource Using Incompatible Type ('Type Confusion')
Product status
References
github.com/...iccDEV/security/advisories/GHSA-p85g-f9q7-jmjx
github.com/InternationalColorConsortium/iccDEV/issues/358
github.com/...ommit/7ff76d1471077172f9659de8d9536443eac7c48f