Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x69c-qfxw-mhm7

Опубликовано: 09 апр. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

A heap buffer overflow vulnerability exists during the decoding of PALETTE COLOR DICOM images. Pixel length validation uses 32-bit multiplication for width and height calculations. If these values overflow, the validation check incorrectly succeeds, allowing the decoder to read and write to memory beyond allocated buffers.

A heap buffer overflow vulnerability exists during the decoding of PALETTE COLOR DICOM images. Pixel length validation uses 32-bit multiplication for width and height calculations. If these values overflow, the validation check incorrectly succeeds, allowing the decoder to read and write to memory beyond allocated buffers.

EPSS

Процентиль: 43%
0.0057
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-787

Связанные уязвимости

CVSS3: 9.8
ubuntu
4 месяца назад

A heap buffer overflow vulnerability exists during the decoding of `PALETTE COLOR` DICOM images. Pixel length validation uses 32-bit multiplication for width and height calculations. If these values overflow, the validation check incorrectly succeeds, allowing the decoder to read and write to memory beyond allocated buffers.

CVSS3: 9.8
nvd
4 месяца назад

A heap buffer overflow vulnerability exists during the decoding of `PALETTE COLOR` DICOM images. Pixel length validation uses 32-bit multiplication for width and height calculations. If these values overflow, the validation check incorrectly succeeds, allowing the decoder to read and write to memory beyond allocated buffers.

CVSS3: 9.8
debian
4 месяца назад

A heap buffer overflow vulnerability exists during the decoding of `PA ...

EPSS

Процентиль: 43%
0.0057
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-787