Sante DICOM Viewer Pro JP2 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
CVE-2023-34297

8.8HIGH

Key Information:

Vendor

Sante

Vendor
CVE Published:
3 May 2024

What is CVE-2023-34297?

A vulnerability exists within the Sante DICOM Viewer Pro's handling of JP2 file format that allows for out-of-bounds writes. This flaw stems from the insufficient validation of user-supplied data when parsing JP2 files. An attacker exploiting this vulnerability can execute arbitrary code by enticing users to open infected files or visit malicious webpages containing crafted JP2 files. Successful exploitation could compromise the integrity of the current process, enabling unauthorized actions on the affected system. Reference advisory: ZDI-23-856.

Affected Version(s)

DICOM Viewer Pro 12.2.3.0

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.