Alerts This Week
Warning Icon 1 923
Alerts This Week
Warning Icon 1 923

Debian 10: DLA-3847-1 Medium: Memory Management Issues in DCMTK

debian lts
Calendar Grey June 28, 2024
Dist Debian Esm H88
The security notice DLA-3847-1 highlights various vulnerabilities found in DCMTK, the toolkit utilized for DICOM medical imaging. It is advisable to perform an upgrade.
Multiple vulnerabilities havebenn fixed in DCMTK, a collection of libraries and applications implementing large parts the DICOM standard for medical images

Summary

CVE-2021-41687

Incorrect freeing of memory

CVE-2021-41688

Incorrect freeing of memory

CVE-2021-41689

NULL pointer dereference

CVE-2021-41690

Incorrect freeing of memory

CVE-2022-2121

NULL pointer dereference

CVE-2022-43272

Memory leak in single process mode

CVE-2024-28130

Segmentation faults due to incorrect typecast

CVE-2024-34508

Segmentation fault via invalid DIMSE message

CVE-2024-34509

Segmentation fault via invalid DIMSE message

For Debian 10 buster, these problems have been fixed in version
3.6.4-2.1+deb10u1.

We recommend that you upgrade your dcmtk packages.

For the detailed security status of dcmtk please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/dcmtk

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
medium
Lowest
Low
Medium
High
Critical

Package: dcmtk
Version: 3.6.4-2.1+deb10u1
CVE ID: CVE-2021-41687 CVE-2021-41688 CVE-2021-41689 CVE-2021-41690
Debian Bug: 1014044 1027165 1070207

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here