Bug ID 1201181
Summary VUL-0: CVE-2021-41690: dcmtk: malloced memory for storing all file information are recorded in a global variable LST and are not freed properly
Classification openSUSE
Product openSUSE Distribution
Version Leap 15.4
Hardware Other
URL https://smash.suse.de/issue/335773/
OS Other
Status NEW
Severity Minor
Priority P5 - None
Component Basesystem
Assignee screening-team-bugs@suse.de
Reporter abergmann@suse.com
QA Contact security-team@suse.de
Found By Security Response Team
Blocker ---

CVE-2021-41690

DCMTK through 3.6.6 does not handle memory free properly. The malloced memory
for storing all file information are recorded in a global variable LST and are
not freed properly. Sending specific requests to the dcmqrdb program can incur
a
memory leak. An attacker can use it to launch a DoS attack.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-41690
https://github.com/DCMTK/dcmtk/commit/a9697dfeb672b0b9412c00c7d36d801e27ec85cb
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-41690
https://github.com/DCMTK/dcmtk


You are receiving this mail because: