漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
iccDEV vulnerable to Stack-based Buffer Overflow in CIccTagFloatNum::GetValues()
Vulnerability Description
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.3, there is a stack-buffer-overflow vulnerability in CIccTagFloatNum<>::GetValues(). This is triggered when processing a malformed ICC profile. The vulnerability allows an out-of-bounds write on the stack, potentially leading to memory corruption, information disclosure, or code execution when processing specially crafted ICC files. This issue has been patched in version 2.3.1.3.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Vulnerability Type
内存缓冲区边界内操作的限制不恰当
Vulnerability Title
iccDEV 安全漏洞
Vulnerability Description
iccDEV是International Color Consortium开源的一个颜色配置代码库。 iccDEV 2.3.1.3之前版本存在安全漏洞,该漏洞源于CIccTagFloatNum<>::GetValues函数存在栈缓冲区溢出,可能导致处理特制ICC文件时越界写入、内存损坏、信息泄露或代码执行。
CVSS Information
N/A
Vulnerability Type
N/A