Bug ID 1223324
Summary VUL-0: CVE-2024-28130: dcmtk: incorrect type conversion in the DVPSSoftcopyVOI_PList:createFromImage functionality of OFFIS DCMTK
Classification openSUSE
Product openSUSE Distribution
Version Leap 15.6
Hardware Other
URL https://smash.suse.de/issue/402934/
OS Other
Status NEW
Severity Major
Priority P5 - None
Component KDE Applications
Assignee christophe@krop.fr
Reporter smash_bz@suse.de
QA Contact security-team@suse.de
CC camila.matos@suse.com
Target Milestone ---
Found By Security Response Team
Blocker ---

An incorrect type conversion vulnerability exists in the
DVPSSoftcopyVOI_PList::createFromImage functionality of OFFIS DCMTK 3.6.8. A
specially crafted malformed file can lead to arbitrary code execution. An
attacker can provide a malicious file to trigger this vulnerability.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-28130
https://www.cve.org/CVERecord?id=CVE-2024-28130
https://talosintelligence.com/vulnerability_reports/TALOS-2024-1957


You are receiving this mail because: