Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Omar Ganiev

Researcher fromDeteAct Team, Open Medical Infrastructure Security Project
#27139of 56,331
9.8Total CVSS
Vulnerabilities · 1
PT-2019-11520
9.8
2019-01-20
Dcmtk · Dcmtk · CVE-2019-1010228
Name of the Vulnerable Software and Affected Versions: DCMTK versions 3.6.3 and below Description: The issue affects the DcmRLEDecoder component, specifically the decompress() function in the dcrledec.h file. It can lead to a buffer overflow, resulting in possible code execution and confirmed Denial of Service. This can occur in various scenarios of DICOM file processing, such as DICOM to image conversion. Recommendations: For DCMTK versions 3.6.3 and below, update to version 3.6.4 or later to resolve the issue. As a temporary workaround, consider restricting the use of the DcmRLEDecoder component, specifically the decompress() function, until the update is applied.