Sante DICOM Viewer Pro JP2 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
CVE-2023-34297
8.8HIGH
What is CVE-2023-34297?
A vulnerability exists within the Sante DICOM Viewer Pro's handling of JP2 file format that allows for out-of-bounds writes. This flaw stems from the insufficient validation of user-supplied data when parsing JP2 files. An attacker exploiting this vulnerability can execute arbitrary code by enticing users to open infected files or visit malicious webpages containing crafted JP2 files. Successful exploitation could compromise the integrity of the current process, enabling unauthorized actions on the affected system. Reference advisory: ZDI-23-856.
Affected Version(s)
DICOM Viewer Pro 12.2.3.0
