Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-50003

Опубликовано: 30 июн. 2026
Источник: debian

Описание

A malicious or compromised server can make a DCMTK client using bit-preserving C-GET storage mode write files outside the chosen output directory, using both relative (../) paths and absolute paths.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
dcmtkfixed3.7.0+really3.7.0-7package
dcmtkno-dsatrixiepackage
dcmtkpostponedbookwormpackage
dcmtkpostponedbullseyepackage

Примечания

  • Fixed by: https://git.dcmtk.org/?p=dcmtk.git;a=commit;h=eca9a03dda7d4fc1faa7e5a6dac9617938cf5803

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 1 месяца назад

A malicious or compromised server can make a DCMTK client using bit-preserving C-GET storage mode write files outside the chosen output directory, using both relative (../) paths and absolute paths.

CVSS3: 9.8
nvd
около 1 месяца назад

A malicious or compromised server can make a DCMTK client using bit-preserving C-GET storage mode write files outside the chosen output directory, using both relative (../) paths and absolute paths.

CVSS3: 9.8
github
около 1 месяца назад

A malicious or compromised server can make a DCMTK client using bit-preserving C-GET storage mode write files outside the chosen output directory, using both relative (../) paths and absolute paths.