PT-2024-22280 · Offis+5 · Dcmtk+5

Emmanuel Tacheau

·

Published

2024-03-14

·

Updated

2025-09-10

·

CVE-2024-28130

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions OFFIS DCMTK version 3.6.8
Description An incorrect type conversion vulnerability exists in the DVPSSoftcopyVOI PList::createFromImage functionality. A specially crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
Recommendations For OFFIS DCMTK version 3.6.8, consider avoiding the use of the DVPSSoftcopyVOI PList::createFromImage functionality until a patch is available. As a temporary workaround, restrict the handling of malformed files to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Incorrect Type Conversion or Cast

Weakness Enumeration

Related Identifiers

BDU:2025-01309
CVE-2024-28130
DLA-3847-1
DLA-4038-1
DLA-4038-2
MGASA-2024-0251
OPENSUSE-SU-2024:0113-1
OPENSUSE-SU-2024:13898-1
USN-7010-1

Affected Products

Astra Linux
Dcmtk
Debian
Linuxmint
Red Os
Ubuntu