Description
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to 2.3.1.4, SrcPixel and DestPixel stack buffers overlap in CIccTagMultiProcessElement::Apply() int IccTagMPE.cpp. This vulnerability is fixed in 2.3.1.4.
Problem types
CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CWE-123: Write-what-where Condition
CWE-628: Function Call with Incorrectly Specified Arguments
CWE-682: Incorrect Calculation
Product status
References
github.com/...iccDEV/security/advisories/GHSA-35rg-jcmp-583h
github.com/InternationalColorConsortium/iccDEV/issues/577
github.com/InternationalColorConsortium/iccDEV/pull/579
github.com/...ommit/9206e0b8684e4cf4186d9ae768f16760bc1af9ff
github.com/...alColorConsortium/iccDEV/releases/tag/v2.3.1.4