An out-of-bounds read vulnerability exists in the RAWCodec::DecodeBytes functionality of Mathieu Malaterre Grassroot DICOM 3.0.23. A specially crafted DICOM file can lead to an out-of-bounds read. An attacker can provide a malicious file to trigger this vulnerability.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "3.0.24-3build1", "binary_name": "gdcm-doc" }, { "binary_version": "3.0.24-3build1", "binary_name": "libgdcm-cil" }, { "binary_version": "3.0.24-3build1", "binary_name": "libgdcm-cil-dbgsym" }, { "binary_version": "3.0.24-3build1", "binary_name": "libgdcm-dev" }, { "binary_version": "3.0.24-3build1", "binary_name": "libgdcm-java" }, { "binary_version": "3.0.24-3build1", "binary_name": "libgdcm-java-dbgsym" }, { "binary_version": "3.0.24-3build1", "binary_name": "libgdcm-tools" }, { "binary_version": "3.0.24-3build1", "binary_name": "libgdcm-tools-dbgsym" }, { "binary_version": "3.0.24-3build1", "binary_name": "libgdcm3.0t64" }, { "binary_version": "3.0.24-3build1", "binary_name": "libgdcm3.0t64-dbgsym" }, { "binary_version": "3.0.24-3build1", "binary_name": "libvtkgdcm-9.1t64" }, { "binary_version": "3.0.24-3build1", "binary_name": "libvtkgdcm-9.1t64-dbgsym" }, { "binary_version": "3.0.24-3build1", "binary_name": "libvtkgdcm-dev" }, { "binary_version": "3.0.24-3build1", "binary_name": "libvtkgdcm-tools" }, { "binary_version": "3.0.24-3build1", "binary_name": "libvtkgdcm-tools-dbgsym" }, { "binary_version": "3.0.24-3build1", "binary_name": "python3-gdcm" }, { "binary_version": "3.0.24-3build1", "binary_name": "python3-gdcm-dbgsym" }, { "binary_version": "3.0.24-3build1", "binary_name": "python3-vtkgdcm" }, { "binary_version": "3.0.24-3build1", "binary_name": "python3-vtkgdcm-dbgsym" } ] }