DCMTK through 3.6.6 does not handle memory free properly. The program malloc a heap memory for parsing data, but does not free it when error in parsing. Sending specific requests to the dcmqrdb program incur the memory leak. An attacker can use it to launch a DoS attack.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade dcmtk | Jul 3, 2024 | Jun 28, 2022 |
| Ubuntu | — | Upgrade dcmtk (Ubuntu Pro)Upgrade libdcmtk17Upgrade libdcmtk12 (Ubuntu Pro)Upgrade dcmtkUpgrade libdcmtk5 (Ubuntu Pro)Upgrade libdcmtk14Upgrade libdcmtk17t64 (Ubuntu Pro)Upgrade libdcmtk14 (Ubuntu Pro)Upgrade libdcmtk16 (Ubuntu Pro) | Mar 22, 2023 | Jun 28, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub