Heap-based buffer overflow in iccDEV - CVE-2026-34539
Published: May 5, 2026
iccDEV
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to heap-based buffer overflow in CTiffImg::WriteLine() when processing a crafted ICC profile and TIFF input. A remote attacker can supply a malicious .icc and .tif pair to cause a denial of service.
The issue is observable as an out-of-bounds heap read during TIFF strip writing in iccSpecSepToTiff.