Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2024:0168-1

Опубликовано: 18 июн. 2024
Источник: suse-cvrf

Описание

Security update for gdcm

This update for gdcm fixes the following issues:

  • CVE-2024-22373: Fixed out-of-bounds write vulnerability in JPEG2000Codec::DecodeByStreamsCommon (boo#1223398).

Список пакетов

SUSE Package Hub 15 SP6
gdcm-3.0.24-bp156.2.4.1
gdcm-applications-3.0.24-bp156.2.4.1
gdcm-devel-3.0.24-bp156.2.4.1
gdcm-examples-3.0.24-bp156.2.4.1
libgdcm3_0-3.0.24-bp156.2.4.1
libsocketxx1_2-3.0.24-bp156.2.4.1
python3-gdcm-3.0.24-bp156.2.4.1
openSUSE Leap 15.6
gdcm-3.0.24-bp156.2.4.1
gdcm-applications-3.0.24-bp156.2.4.1
gdcm-devel-3.0.24-bp156.2.4.1
gdcm-examples-3.0.24-bp156.2.4.1
libgdcm3_0-3.0.24-bp156.2.4.1
libsocketxx1_2-3.0.24-bp156.2.4.1
python3-gdcm-3.0.24-bp156.2.4.1

Описание

An out-of-bounds write vulnerability exists in the JPEG2000Codec::DecodeByStreamsCommon functionality of Mathieu Malaterre Grassroot DICOM 3.0.23. A specially crafted DICOM file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.


Затронутые продукты
SUSE Package Hub 15 SP6:gdcm-3.0.24-bp156.2.4.1
SUSE Package Hub 15 SP6:gdcm-applications-3.0.24-bp156.2.4.1
SUSE Package Hub 15 SP6:gdcm-devel-3.0.24-bp156.2.4.1
SUSE Package Hub 15 SP6:gdcm-examples-3.0.24-bp156.2.4.1

Ссылки