PT-2024-10423 · Dcmtk+5 · Dcmtk+5

Nils Bars

·

Published

2024-03-13

·

Updated

2025-09-10

·

CVE-2024-34509

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions DCMTK versions prior to 3.6.9
Description The issue is related to a segmentation fault in the dcmdata component of the DCMTK library, which can be triggered by an invalid DIMSE message. This can potentially allow a remote attacker to cause a denial of service.
Recommendations For versions prior to 3.6.9, update to version 3.6.9 or later to resolve the issue. As a temporary workaround, consider restricting access to the dcmdata component to minimize the risk of exploitation.

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2025-00955
CVE-2024-34509
DLA-3847-1
DLA-4038-1
DLA-4038-2
MGASA-2024-0251
OPENSUSE-SU-2024:14514-1
OPENSUSE-SU-2025:0053-1
USN-7010-1

Affected Products

Astra Linux
Dcmtk
Debian
Linuxmint
Red Os
Ubuntu