PT-2025-2931 · Offis+4 · Dcmtk+4
Emmanuel Tacheau
·
Published
2024-12-16
·
Updated
2025-09-29
·
CVE-2024-52333
CVSS v3.1
8.4
High
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OFFIS DCMTK version 3.6.8
Description
An improper array index validation issue exists in the
determineMinMax functionality. A specially crafted DICOM file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this issue, potentially exploiting the improper array index validation in the determineMinMax function.Recommendations
For OFFIS DCMTK version 3.6.8, consider disabling the
determineMinMax function until a patch is available to prevent potential out-of-bounds writes. Restrict access to handling DICOM files to minimize the risk of exploitation. Avoid using potentially malicious DICOM files until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this issue.Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Dcmtk
Debian
Red Os