CVE-2026-34549 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, there is an Undefined Behavior (UB) condi…
Medium CVSS: 6.2

CVE-2026-34549

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, there is an Undefined Behavior (UB) condition in IccUtil.cpp triggered by a crafted input profile. Under UndefinedBehaviorSanitizer, the issue is reported as invalid left shift operations on icUInt32Number (unsigned 32-bit) where the shifted value “cannot be represented” in that type. This issue has been patched in version 2.3.1.6.
Vendor
-
Product
-
CWE
CWE-758
Yayın Tarihi
2026-03-31 23:17:09
Güncelleme
2026-04-01 14:23:37
Source Identifier
security-advisories@github.com
KEV Date Added
-

Kategoriler

Referanslar