Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-60669
HistoryJun 30, 2022 - 12:00 a.m.

DCMTK Heap Buffer Overflow Vulnerability (CNVD-2022-60669)

2022-06-3000:00:00
China National Vulnerability Database
www.cnvd.org.cn
11

0.001 Low

EPSS

Percentile

46.8%

DCMTK is a collection of libraries and applications from DCMTK open source that implement most DICOM standards. Software for inspecting, building and converting DICOM image files, handling offline media, sending and receiving images over a network connection, and demo image storage and worklist servers.DCMTK 3.6.6 and earlier versions contain a heap buffer overflow vulnerability that stems from the program’s failure to properly handle string copying. An attacker could exploit this vulnerability to launch a denial-of-service attack.

CPENameOperatorVersion
dcmtk dcmtk <=eq3.6.6