A heap-based buffer overflow vulnerability exists in the LookupTable::SetLUT functionality of Mathieu Malaterre Grassroot DICOM 3.0.23. A specially crafted malformed file can lead to memory corruption. An attacker can provide a malicious file to trigger this vulnerability.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "3.0.24-3build1", "binary_name": "gdcm-doc" }, { "binary_version": "3.0.24-3build1", "binary_name": "libgdcm-cil" }, { "binary_version": "3.0.24-3build1", "binary_name": "libgdcm-cil-dbgsym" }, { "binary_version": "3.0.24-3build1", "binary_name": "libgdcm-dev" }, { "binary_version": "3.0.24-3build1", "binary_name": "libgdcm-java" }, { "binary_version": "3.0.24-3build1", "binary_name": "libgdcm-java-dbgsym" }, { "binary_version": "3.0.24-3build1", "binary_name": "libgdcm-tools" }, { "binary_version": "3.0.24-3build1", "binary_name": "libgdcm-tools-dbgsym" }, { "binary_version": "3.0.24-3build1", "binary_name": "libgdcm3.0t64" }, { "binary_version": "3.0.24-3build1", "binary_name": "libgdcm3.0t64-dbgsym" }, { "binary_version": "3.0.24-3build1", "binary_name": "libvtkgdcm-9.1t64" }, { "binary_version": "3.0.24-3build1", "binary_name": "libvtkgdcm-9.1t64-dbgsym" }, { "binary_version": "3.0.24-3build1", "binary_name": "libvtkgdcm-dev" }, { "binary_version": "3.0.24-3build1", "binary_name": "libvtkgdcm-tools" }, { "binary_version": "3.0.24-3build1", "binary_name": "libvtkgdcm-tools-dbgsym" }, { "binary_version": "3.0.24-3build1", "binary_name": "python3-gdcm" }, { "binary_version": "3.0.24-3build1", "binary_name": "python3-gdcm-dbgsym" }, { "binary_version": "3.0.24-3build1", "binary_name": "python3-vtkgdcm" }, { "binary_version": "3.0.24-3build1", "binary_name": "python3-vtkgdcm-dbgsym" } ] }