Bug ID 1201178
Summary VUL-0: CVE-2021-41687: dcmtk: the program malloc a heap memory for parsing data, but does not free it when error in parsing
Classification openSUSE
Product openSUSE Distribution
Version Leap 15.4
Hardware Other
URL https://smash.suse.de/issue/335776/
OS Other
Status NEW
Severity Minor
Priority P5 - None
Component Basesystem
Assignee screening-team-bugs@suse.de
Reporter abergmann@suse.com
QA Contact security-team@suse.de
Found By Security Response Team
Blocker ---

CVE-2021-41687

DCMTK through 3.6.6 does not handle memory free properly. The program malloc a
heap memory for parsing data, but does not free it when error in parsing.
Sending specific requests to the dcmqrdb program incur the memory leak. An
attacker can use it to launch a DoS attack.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-41687
https://github.com/DCMTK/dcmtk/commit/a9697dfeb672b0b9412c00c7d36d801e27ec85cb
https://github.com/DCMTK/dcmtk
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-41687


You are receiving this mail because: