[Bug 1208637] New: VUL-0: CVE-2022-2119: dcmtk: path traversal vulnerability
https://bugzilla.suse.com/show_bug.cgi?id=1208637 Bug ID: 1208637 Summary: VUL-0: CVE-2022-2119: dcmtk: path traversal vulnerability Classification: openSUSE Product: openSUSE Distribution Version: Leap 15.4 Hardware: Other URL: https://smash.suse.de/issue/335512/ OS: Other Status: NEW Severity: Normal Priority: P5 - None Component: Security Assignee: kde-maintainers@suse.de Reporter: gabriele.sonnu@suse.com QA Contact: qa-bugs@suse.de CC: security-team@suse.de Found By: Security Response Team Blocker: --- OFFIS DCMTK's (All versions prior to 3.6.7) service class provider (SCP) is vulnerable to path traversal, allowing an attacker to write DICOM files into arbitrary directories under controlled names. This could allow remote code execution. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-2119 https://bugzilla.redhat.com/show_bug.cgi?id=2173038 https://www.cve.org/CVERecord?id=CVE-2022-2119 https://www.cisa.gov/uscert/ics/advisories/icsma-22-174-01 -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1208637 https://bugzilla.suse.com/show_bug.cgi?id=1208637#c1 --- Comment #1 from Gabriele Sonnu <gabriele.sonnu@suse.com> --- Only openSUSE:Backports:SLE-15-SP4/dcmtk (v3.6.6) is affected. -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1208637 Gabriele Sonnu <gabriele.sonnu@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- QA Contact|qa-bugs@suse.de |security-team@suse.de -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1208637 Maintenance Automation <maint-coord+maintenance-robot@suse.de> changed: What |Removed |Added ---------------------------------------------------------------------------- Priority|P5 - None |P3 - Medium -- You are receiving this mail because: You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@suse.com