CVE-2013-6825

See a problem?
Source
https://nvd.nist.gov/vuln/detail/CVE-2013-6825
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2013-6825.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2013-6825
Published
2014-06-10T14:55:09Z
Modified
2024-06-30T12:01:22Z
Summary
[none]
Details

(1) movescu.cc and (2) storescp.cc in dcmnet/apps/, (3) dcmnet/libsrc/scp.cc, (4) dcmwlm/libsrc/wlmactmg.cc, (5) dcmprscp.cc and (6) dcmpsrcv.cc in dcmpstat/apps/, (7) dcmpstat/tests/msgserv.cc, and (8) dcmqrdb/apps/dcmqrscp.cc in DCMTK 3.6.1 and earlier does not check the return value of the setuid system call, which allows local users to gain privileges by creating a large number of processes.

References

Affected packages

Debian:11 / dcmtk

Package

Name
dcmtk
Purl
pkg:deb/debian/dcmtk?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.6.1~20150629-1

Ecosystem specific

{
    "urgency": "unimportant"
}

Debian:12 / dcmtk

Package

Name
dcmtk
Purl
pkg:deb/debian/dcmtk?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.6.1~20150629-1

Ecosystem specific

{
    "urgency": "unimportant"
}

Debian:13 / dcmtk

Package

Name
dcmtk
Purl
pkg:deb/debian/dcmtk?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.6.1~20150629-1

Ecosystem specific

{
    "urgency": "unimportant"
}