DCMTK through 3.6.6 does not handle string copy properly. Sending specific requests to the dcmqrdb program, it would query its database and copy the result even if the result is null, which can incur a head-based overflow. An attacker can use it to launch a DoS attack.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade dcmtk | Jul 3, 2024 | Jun 28, 2022 |
| Ubuntu | — | Upgrade libdcmtk5 (Ubuntu Pro)Upgrade libdcmtk14 (Ubuntu Pro)Upgrade dcmtkUpgrade libdcmtk17Upgrade libdcmtk14Upgrade libdcmtk16 (Ubuntu Pro)Upgrade libdcmtk17t64 (Ubuntu Pro)Upgrade dcmtk (Ubuntu Pro)Upgrade libdcmtk12 (Ubuntu Pro) | Mar 22, 2023 | Jun 28, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub