vulnerability
SUSE: CVE-2022-2120: SUSE Linux Security Advisory
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 8 | (AV:N/AC:L/Au:N/C:P/I:P/A:P) | Jun 24, 2022 | Oct 26, 2022 | May 16, 2023 |
Severity
8
CVSS
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
Published
Jun 24, 2022
Added
Oct 26, 2022
Modified
May 16, 2023
Description
OFFIS DCMTK's (All versions prior to 3.6.7) service class user (SCU) is vulnerable to relative path traversal, allowing an attacker to write DICOM files into arbitrary directories under controlled names. This could allow remote code execution.
Solutions
suse-upgrade-dcmtksuse-upgrade-dcmtk-develsuse-upgrade-gdcmsuse-upgrade-gdcm-applicationssuse-upgrade-gdcm-develsuse-upgrade-gdcm-examplessuse-upgrade-libdcmtk17suse-upgrade-libgdcm3_0suse-upgrade-libsocketxx1_2suse-upgrade-orthancsuse-upgrade-orthanc-develsuse-upgrade-orthanc-docsuse-upgrade-orthanc-gdcmsuse-upgrade-orthanc-sourcesuse-upgrade-orthanc-webviewersuse-upgrade-python3-gdcm
Rapid7 Labs
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.