Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-41688

Опубликовано: 28 июн. 2022
Источник: debian
EPSS Низкий

Описание

DCMTK through 3.6.6 does not handle memory free properly. The object in the program is free but its address is still used in other locations. Sending specific requests to the dcmqrdb program will incur a double free. An attacker can use it to launch a DoS attack.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
dcmtkfixed3.6.7-1package

Примечания

  • https://github.com/DCMTK/dcmtk/commit/a9697dfeb672b0b9412c00c7d36d801e27ec85cb (DCMTK-3.6.7)

EPSS

Процентиль: 24%
0.00076
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 3 года назад

DCMTK through 3.6.6 does not handle memory free properly. The object in the program is free but its address is still used in other locations. Sending specific requests to the dcmqrdb program will incur a double free. An attacker can use it to launch a DoS attack.

CVSS3: 7.5
nvd
почти 3 года назад

DCMTK through 3.6.6 does not handle memory free properly. The object in the program is free but its address is still used in other locations. Sending specific requests to the dcmqrdb program will incur a double free. An attacker can use it to launch a DoS attack.

CVSS3: 7.5
github
почти 3 года назад

DCMTK through 3.6.6 does not handle memory free properly. The object in the program is free but its address is still used in other locations. Sending specific requests to the dcmqrdb program will incur a double free. An attacker can use it to launch a DoS attack.

CVSS3: 7.5
fstec
больше 3 лет назад

Уязвимость библиотеки для работы с форматом DICOM DCMTK, связанная с повторным освобождением памяти, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
redos
почти 4 года назад

Множественные уязвимости dcmtk

EPSS

Процентиль: 24%
0.00076
Низкий