OFFIS DCMTK's (All versions prior to 3.6.7) service class provider (SCP) is vulnerable to path traversal, allowing an attacker to write DICOM files into arbitrary directories under controlled names. This could allow remote code execution.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade dcmtk | Jul 30, 2024 | Jun 24, 2022 |
| Suse | — | Upgrade dcmtk-develUpgrade libgdcm3_0Upgrade dcmtkUpgrade python3-gdcmUpgrade gdcm-applicationsUpgrade libsocketxx1_2Upgrade orthanc-develUpgrade orthanc-docUpgrade orthanc-webviewerUpgrade gdcm-develUpgrade gdcm-examplesUpgrade orthanc-sourceUpgrade gdcmUpgrade libdcmtk17Upgrade orthanc-gdcmUpgrade orthanc | Oct 26, 2022 | Jun 24, 2022 |
| Ubuntu | — | Upgrade libdcmtk17Upgrade libdcmtk14 (Ubuntu Pro)Upgrade libdcmtk12 (Ubuntu Pro)Upgrade dcmtkUpgrade libdcmtk5 (Ubuntu Pro)Upgrade dcmtk (Ubuntu Pro)Upgrade libdcmtk16 (Ubuntu Pro) | Mar 22, 2023 | Jun 24, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub