PT-2024-19372 · Mathieu Malaterre+2 · Grassroot Dicom+2

Emmanuel Tacheau

·

Published

2024-02-15

·

Updated

2026-02-10

·

CVE-2024-22373

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Mathieu Malaterre Grassroot DICOM version 3.0.23
Description An out-of-bounds write issue exists in the JPEG2000Codec::DecodeByStreamsCommon functionality. A specially crafted DICOM file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this issue.
Recommendations For Mathieu Malaterre Grassroot DICOM version 3.0.23, consider avoiding the use of the JPEG2000Codec::DecodeByStreamsCommon functionality until a patch is available. As a temporary workaround, restrict the handling of DICOM files from untrusted sources to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Memory Corruption

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2025-03941
CVE-2024-22373
OPENSUSE-SU-2024:0167-1
OPENSUSE-SU-2024:0168-1
OPENSUSE-SU-2025:15546-1
OPENSUSE-SU-2026:20193-1

Affected Products

Astra Linux
Debian
Grassroot Dicom