CVE-2024-38427: High severity international color consortium demoiccmax vulnerability
Published Jun 16, 2024
·Updated
In International Color Consortium DemoIccMAX before 85ce74e, a logic flaw in CIccTagXmlProfileSequenceId::ParseXml in IccXML/IccLibXML/IccTagXml.cpp results in unconditionally returning false.
Affected Software
1 affected component
International Color Consortium DemoIccMAX<85ce74e
Event History
Jun 16, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability severity of CVE-2024-38427?
The severity of CVE-2024-38427 is classified as moderate due to its logic flaw that can potentially lead to unintended behavior.
2
How do I fix CVE-2024-38427?
To fix CVE-2024-38427, update your DemoIccMAX software to version 85ce74e or later, which addresses the logic flaw.
3
What components are affected by CVE-2024-38427?
CVE-2024-38427 affects the CIccTagXmlProfileSequenceId component in International Color Consortium DemoIccMAX.
4
What type of vulnerability is CVE-2024-38427?
CVE-2024-38427 is a logic flaw vulnerability that affects XML parsing functionality.
5
Is there a workaround for CVE-2024-38427 before applying a patch?
There are no known workarounds for CVE-2024-38427; the recommended action is to apply the available patch.