PT-2025-42892 · Dcmtk+1 · Dcmtk+1

Zh_Vul

·

Publicado

2025-10-21

·

Atualizado

2025-11-03

·

CVE-2020-36855

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions DCMTK versions up to 3.6.5
Description A security issue exists in DCMTK related to the parseQuota function within the dcmqrscp component. Manipulation of the StorageQuota argument can lead to a stack-based buffer overflow. Local access is required for exploitation, and the exploit has been publicly disclosed.
Recommendations Upgrade to version 3.6.6 or later to address this issue.

Exploit

Correção

Buffer Overflow

Stack Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2025-16069
CVE-2020-36855
DLA-4363-1

Produtos afetados

Dcmtk
Debian