CVE-2023-46603

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Oct 23, 2023
Updated: Jan 9, 2024
CWE ID 125

Summary

CVE-2023-46603 is a newly identified vulnerability affecting International Color Consortium (ICC) DemoIccMAX. An out-of-bounds read issue was discovered in the CIccPRMG::GetChroma function, located in IccProfLib/IccPrmg.cpp within the library file libSampleICC.a. This flaw allows an attacker to read memory outside of the designated boundaries, potentially exposing sensitive data or causing the system to crash. The impact of this vulnerability could lead to information disclosure or denial of service, necessitating prompt patching or mitigation measures.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share