Description
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, iccDEV is vulnerable to NULL pointer dereference via the XML calculator parser. This issue has been patched in version 2.3.1.2.
Problem types
CWE-20: Improper Input Validation
CWE-252: Unchecked Return Value
CWE-476: NULL Pointer Dereference
CWE-690: Unchecked Return Value to NULL Pointer Dereference
Product status
References
github.com/...iccDEV/security/advisories/GHSA-6822-qvxq-m736
github.com/InternationalColorConsortium/iccDEV/issues/375
github.com/InternationalColorConsortium/iccDEV/pull/404
github.com/...ommit/75f124f40ba45491211cb4b67f0e05b7c7d59553
github.com/...ommit/bdfa31940726aaabb0a6f19194d9062ba0598959