Описание
A malicious or compromised server can make a DCMTK client using bit-preserving C-GET storage mode write files outside the chosen output directory, using both relative (../) paths and absolute paths.
EPSS
Процентиль: 40%
0.00497
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-22
Связанные уязвимости
CVSS3: 9.8
ubuntu
около 1 месяца назад
A malicious or compromised server can make a DCMTK client using bit-preserving C-GET storage mode write files outside the chosen output directory, using both relative (../) paths and absolute paths.
CVSS3: 9.8
debian
около 1 месяца назад
A malicious or compromised server can make a DCMTK client using bit-pr ...
CVSS3: 9.8
github
около 1 месяца назад
A malicious or compromised server can make a DCMTK client using bit-preserving C-GET storage mode write files outside the chosen output directory, using both relative (../) paths and absolute paths.
EPSS
Процентиль: 40%
0.00497
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-22