CVE-2023-46603
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Oct 23, 2023
Updated: Jan 9, 2024
CWE ID 125
Summary
CVE-2023-46603 is a newly identified vulnerability affecting International Color Consortium (ICC) DemoIccMAX. An out-of-bounds read issue was discovered in the CIccPRMG::GetChroma function, located in IccProfLib/IccPrmg.cpp within the library file libSampleICC.a. This flaw allows an attacker to read memory outside of the designated boundaries, potentially exposing sensitive data or causing the system to crash. The impact of this vulnerability could lead to information disclosure or denial of service, necessitating prompt patching or mitigation measures.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Vendors
- Color