CVE-2024-27628

unknown
Published — · Modified —
CVSS v3
CVSS v4 NEW
not yet in upstream
VIR risk

Description

Buffer Overflow vulnerability in DCMTK v.3.6.8 allows an attacker to execute arbitrary code via the EctEnhancedCT method component.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Debian Security Tracker · View original ↗ · DFSG

CVE-2024-27628 NameCVE-2024-27628 DescriptionBuffer Overflow vulnerability in DCMTK v.3.6.8 allows an attacker to execute arbitrary code via the EctEnhancedCT method component. SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) Debian Bugs1074483 Vulnerable and fixed packages The table…

CVE-2024-27628

NameCVE-2024-27628
DescriptionBuffer Overflow vulnerability in DCMTK v.3.6.8 allows an attacker to execute arbitrary code via the EctEnhancedCT method component.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1074483

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
dcmtk (PTS)bullseye3.6.5-1fixed
bullseye (security)3.6.5-1+deb11u6fixed
bookworm3.6.7-9~deb12u3fixed
trixie3.6.9-5fixed
forky3.7.0+really3.7.0-2fixed
sid3.7.0+really3.7.0-3fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
dcmtksourcebuster(not affected)
dcmtksourcebullseye(not affected)
dcmtksourcebookworm3.6.7-9~deb12u2
dcmtksource(unstable)3.6.8-61074483

Notes

[bullseye] - dcmtk <not-affected> (Vulnerable code introduced later)
[buster] - dcmtk <not-affected> (Vulnerable code introduced later)
https://support.dcmtk.org/redmine/issues/1108
https://github.com/DCMTK/dcmtk/commit/ec52e99e1e33fc39810560421c0833b02da567b3
Introduced by: https://github.com/DCMTK/dcmtk/commit/d45c34c076d45b4b04d72f5edd19fb13fad6c1a0 (DCMTK-3.6.5+_20191213)

Home - Debian Security - Source (Git)

Apply commands

text fix
Notes
[bullseye] - dcmtk <not-affected> (Vulnerable code introduced later)[buster] - dcmtk <not-affected> (Vulnerable code introduced later)https://support.dcmtk.org/redmine/issues/1108https://github.com/DCMTK/dcmtk/commit/ec52e99e1e33fc39810560421c0833b02da567b3Introduced by: https://github.com/DCMTK/dcmtk/commit/d45c34c076d45b4b04d72f5edd19fb13fad6c1a0 (DCMTK-3.6.5+_20191213)

OS impact

debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 3.6.8-6
sid Fixed 3.6.8-6
forky Fixed 3.6.8-6
bullseye Fixed 0
bookworm Fixed 3.6.7-9~deb12u2

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.