CVE-2021-41689
Summary
| CVE | CVE-2021-41689 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-06-28 13:15:00 UTC |
| Updated | 2022-07-06 19:44:00 UTC |
| Description | DCMTK through 3.6.6 does not handle string copy properly. Sending specific requests to the dcmqrdb program, it would query its database and copy the result even if the result is null, which can incur a head-based overflow. An attacker can use it to launch a DoS attack. |
Risk And Classification
Problem Types: CWE-476
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Fixed possible NULL pointer dereference. · DCMTK/dcmtk@5c14bf5 · GitHub | MISC | github.com | |
| GitHub - DCMTK/dcmtk: Official DCMTK Github Mirror | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.