PT-2024-20171 · Merge · Merge Dicom Toolkit C/C++

Gabriele Quagliarella

·

Published

2024-05-03

·

Updated

2024-05-03

·

CVE-2024-23914

CVSS v3.1

5.7

Medium

VectorAV:A/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Merge DICOM Toolkit C/C++ versions ≤5.17.0
Description The issue is related to the use of an externally-controlled format string vulnerability in the Merge DICOM Toolkit C/C++ on Windows. When the MC Open Association() function is used to open a DICOM Association and receives a DICOM Application Context Name with illegal characters, it may result in an unhandled exception. The vulnerability is remotely exploitable.
Recommendations For Merge DICOM Toolkit C/C++ versions ≤5.17.0, update to a version higher than 5.17.0 to resolve the issue. As a temporary workaround, consider restricting the input to the MC Open Association() function to prevent the use of illegal characters in the DICOM Application Context Name.

Fix

Use of Externally-Controlled Format String

Weakness Enumeration

Related Identifiers

CVE-2024-23914

Affected Products

Merge Dicom Toolkit C/C++