CVE-2013-6825

high
Published 2014-06-10 Β· Modified 2026-05-06
CVSS v3
β€”
CVSS v4 NEW
β€”
not yet in upstream
VIR risk
7.2

Description

(1) movescu.cc and (2) storescp.cc in dcmnet/apps/, (3) dcmnet/libsrc/scp.cc, (4) dcmwlm/libsrc/wlmactmg.cc, (5) dcmprscp.cc and (6) dcmpsrcv.cc in dcmpstat/apps/, (7) dcmpstat/tests/msgserv.cc, and (8) dcmqrdb/apps/dcmqrscp.cc in DCMTK 3.6.1 and earlier does not check the return value of the setuid system call, which allows local users to gain privileges by creating a large number of processes.

Predictions

Exploit likelihood
20%
Patch ETA
β€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Debian Security Tracker Β· View original β†— Β· DFSG

CVE-2013-6825 NameCVE-2013-6825 Description(1) movescu.cc and (2) storescp.cc in dcmnet/apps/, (3) dcmnet/libsrc/scp.cc, (4) dcmwlm/libsrc/wlmactmg.cc, (5) dcmprscp.cc and (6) dcmpsrcv.cc in dcmpstat/apps/, (7) dcmpstat/tests/msgserv.cc, and (8) dcmqrdb/apps/dcmqrscp.cc in DCMTK 3.6.1 and earlier does not check the return value of the setuid system call, which allows local users to gain…

CVE-2013-6825

NameCVE-2013-6825
Description(1) movescu.cc and (2) storescp.cc in dcmnet/apps/, (3) dcmnet/libsrc/scp.cc, (4) dcmwlm/libsrc/wlmactmg.cc, (5) dcmprscp.cc and (6) dcmpsrcv.cc in dcmpstat/apps/, (7) dcmpstat/tests/msgserv.cc, and (8) dcmqrdb/apps/dcmqrscp.cc in DCMTK 3.6.1 and earlier does not check the return value of the setuid system call, which allows local users to gain privileges by creating a large number of processes.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
dcmtk (PTS)bullseye3.6.5-1fixed
bullseye (security)3.6.5-1+deb11u6fixed
bookworm3.6.7-9~deb12u3fixed
trixie3.6.9-5fixed
forky3.7.0+really3.7.0-2fixed
sid3.7.0+really3.7.0-3fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
dcmtksource(unstable)3.6.1~20150629-1unimportant

Notes

http://hmarco.org/bugs/dcmtk-3.6.1-privilege-escalation.html
Not running with elevated privileges in Debian packaging
http://git.dcmtk.org/web?p=dcmtk.git;a=commitdiff;h=beaf5a5c24101daeeafa48c375120b16197c9e95;hp=5349794c4c458c76609b7aeb53d0ca28cf9fe9f0

Home - Debian Security - Source (Git)

Apply commands

text fix
Notes
http://hmarco.org/bugs/dcmtk-3.6.1-privilege-escalation.htmlNot running with elevated privileges in Debian packaginghttp://git.dcmtk.org/web?p=dcmtk.git;a=commitdiff;h=beaf5a5c24101daeeafa48c375120b16197c9e95;hp=5349794c4c458c76609b7aeb53d0ca28cf9fe9f0

OS impact

debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 3.6.1~20150629-1
sid Fixed 3.6.1~20150629-1
forky Fixed 3.6.1~20150629-1
bullseye Fixed 3.6.1~20150629-1
bookworm Fixed 3.6.1~20150629-1

Application impact

VendorProductVersionsFixed
offisdcmtk{"endIncluding":"3.6.1"}
offisdcmtk3.5.1
offisdcmtk3.5.2
offisdcmtk3.5.2a
offisdcmtk3.5.3
offisdcmtk3.5.4
offisdcmtk3.6.0

References

CWEs

CWE-264

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.