Use-After-Free Vulnerability in Imaging Data Commons libdicom 1.0.5
CVE-2024-24793

9.8CRITICAL

Key Information:

Status
Vendor
CVE Published:
20 February 2024

What is CVE-2024-24793?

A use-after-free vulnerability has been identified in the DICOM Element Parsing implemented in Imaging Data Commons libdicom version 1.0.5. This vulnerability arises when the application processes a specially crafted DICOM file, leading to premature memory deallocation that can be exploited by an attacker. The vulnerability is triggered through the parse_meta_element_create() function during the parsing of the File Meta Information header. If successfully exploited, this could result in unpredictable behavior of the vulnerable application, potentially allowing for further malicious actions.

Affected Version(s)

libdicom 1.0.5

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Discovered by Dimitrios Tatsis of Cisco Talos.
.