CVE-2026-30983: iccDEV has a stack buffer overflow in icFixXml()
Published Mar 10, 2026
·Updated
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is a stack buffer overflow in icFixXml() (strcpy) causing stack memory corruption or crash. This vulnerability is fixed in 2.3.1.5.
Affected Software
2 affected components
iccDEV iccDEV<2.3.1.5
Color iccDEV<2.3.1.5
Remediation
Event History
Mar 10, 2026
CVE Published
via MITRE·05:52 PM
Data Sourced
via MITRE·05:52 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:18 PM
RemedyDescriptionSeverityWeaknessAffected Software
May 6, 58175
Event
via FIRST·03:23 PM
Frequently Asked Questions
1
What is the severity of CVE-2026-30983?
CVE-2026-30983 has a high severity due to the stack buffer overflow potentially leading to stack memory corruption or application crashes.
2
How do I fix CVE-2026-30983?
To fix CVE-2026-30983, update to the version 2.3.1.5 or later of the iccDEV software.
3
What component is affected by CVE-2026-30983?
CVE-2026-30983 affects the icFixXml() function in the iccDEV library.
4
What happens if CVE-2026-30983 is exploited?
Exploitation of CVE-2026-30983 could result in stack memory corruption or application crashes.
5
When was CVE-2026-30983 first identified?
CVE-2026-30983 was identified prior to version 2.3.1.5 of the iccDEV software.