Buffer Overflow Vulnerability in DCMTK Software by Offis
CVE-2024-27628

Currently unrated

Key Information:

Vendor

Offis

Status
Vendor
CVE Published:
28 June 2024

What is CVE-2024-27628?

A buffer overflow vulnerability exists in the DCMTK software version 3.6.8, specifically within the EctEnhancedCT method. This flaw can be exploited by attackers to execute arbitrary code remotely. Such an attack could compromise the integrity and confidentiality of the system where the software is deployed. Users of DCMTK are advised to inspect their implementations and apply any relevant security patches promptly to mitigate potential risks.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.