Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Mageia: 2023-0083 Moderate: DCMTK Denial Of Service Threats

mageia
Calendar Grey March 11, 2023
Dist Mageia Esm H88
Revised DCMTK distributions for Mageia address possible denial of service vulnerabilities and code execution threats identified on 11 Mar 2023.
Gjoko Krstic discovered that DCMTK incorrectly handled buffers

Summary

Gjoko Krstic discovered that DCMTK incorrectly handled buffers. If a user or an automated system were tricked into opening a certain specially crafted input file, a remote attacker could possibly use this issue to cause a denial of service. (CVE-2015-8979)
Omar Ganiev discovered that DCMTK incorrectly handled buffers. If a user or an automated system were tricked into opening a certain specially crafted input file, a remote attacker could possibly use this issue to cause a denial of service. (CVE-2019-1010228)
Jinsheng Ba discovered that DCMTK incorrectly handled certain requests. If a user or an automated system were tricked into opening a certain specially crafted input file, a remote attacker could possibly use this issue to cause a denial of service. (CVE-2021-41687, CVE-2021-41688, CVE-2021-41689, and CVE-2021-41690)
Sharon Brizinov and Noam Moshe discovered that DCMTK incorrectly handled certain inputs. If a user or an automated system were tricked into opening a certain speci...

Read the Full Advisory

References

- https://bugs.mageia.org/show_bug.cgi?id=30790

- https://dicom.offis.de/download/dcmtk/dcmtk367/ANNOUNCE

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/2Z7WVDK43MKWOS23BIN4VCQRQRXHGSDB/

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/WF2FCZOYXVZ4ETCHO62JWUP4D55UWJCV/

- https://ubuntu.com/security/notices/USN-5882-1

- https://www.cve.org/CVERecord?id=CVE-2021-41687

- https://www.cve.org/CVERecord?id=CVE-2021-41688

- https://www.cve.org/CVERecord?id=CVE-2021-41689

- https://www.cve.org/CVERecord?id=CVE-2021-41690

- https://www.cve.org/CVERecord?id=CVE-2022-2119

- https://www.cve.org/CVERecord?id=CVE-2022-2120

- https://www.cve.org/CVERecord?id=CVE-2022-2121

- https://www.cve.org/CVERecord?id=CVE-2022-43272

Resolution

SRPMS

- 8/core/dcmtk-3.6.5-3.1.mga8

Publication date: 11 Mar 2023
URL: https://advisories.mageia.org/MGASA-2023-0083.html
Type: security
CVE: CVE-2021-41687, CVE-2021-41688, CVE-2021-41689, CVE-2021-41690, CVE-2022-2119, CVE-2022-2120, CVE-2022-2121, CVE-2022-43272

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here