Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-558h-5pv9-xxg9

Опубликовано: 29 июн. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

DCMTK through 3.6.6 does not handle string copy properly. Sending specific requests to the dcmqrdb program, it would query its database and copy the result even if the result is null, which can incur a head-based overflow. An attacker can use it to launch a DoS attack.

DCMTK through 3.6.6 does not handle string copy properly. Sending specific requests to the dcmqrdb program, it would query its database and copy the result even if the result is null, which can incur a head-based overflow. An attacker can use it to launch a DoS attack.

EPSS

Процентиль: 24%
0.00078
Низкий

7.5 High

CVSS3

Дефекты

CWE-476

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 3 года назад

DCMTK through 3.6.6 does not handle string copy properly. Sending specific requests to the dcmqrdb program, it would query its database and copy the result even if the result is null, which can incur a head-based overflow. An attacker can use it to launch a DoS attack.

CVSS3: 7.5
nvd
почти 3 года назад

DCMTK through 3.6.6 does not handle string copy properly. Sending specific requests to the dcmqrdb program, it would query its database and copy the result even if the result is null, which can incur a head-based overflow. An attacker can use it to launch a DoS attack.

CVSS3: 7.5
debian
почти 3 года назад

DCMTK through 3.6.6 does not handle string copy properly. Sending spec ...

CVSS3: 7.5
fstec
почти 4 года назад

Уязвимость библиотеки для работы с форматом DICOM DCMTK, связанная с ошибками разыменования указателя, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
redos
почти 4 года назад

Множественные уязвимости dcmtk

EPSS

Процентиль: 24%
0.00078
Низкий

7.5 High

CVSS3

Дефекты

CWE-476