UBUNTU-CVE-2019-1010228
Dashboard / Vulnerabilities / UBUNTU-CVE-2019-1010228
UBUNTU-CVE-2019-1010228
Summary:
Details: OFFIS.de DCMTK 3.6.3 and below is affected by: Buffer Overflow. The impact is: Possible code execution and confirmed Denial of Service. The component is: DcmRLEDecoder::decompress() (file dcrledec.h, line 122). The attack vector is: Many scenarios of DICOM file processing (e.g. DICOM to image conversion). The fixed version is: 3.6.4, after commit 40917614e.
References: https://ubuntu.com/security/CVE-2019-1010228, https://support.dcmtk.org/redmine/issues/858, https://github.com/commontk/DCMTK/commit/40917614e, https://ubuntu.com/security/notices/USN-5882-1, https://www.cve.org/CVERecord?id=CVE-2019-1010228
Affected packages
Package
Name: dcmtk
Purl: pkg:deb/ubuntu/[email protected]~20150924-5ubuntu0.1~esm1?arch=source&distro=esm-apps/xenial
Affected ranges
Type: ECOSYSTEM
Events:
