VYPR

rpm package

suse/dcmtk&distro=SUSE Package Hub 15 SP4

pkg:rpm/suse/dcmtk&distro=SUSE%20Package%20Hub%2015%20SP4

Vulnerabilities (4)

  • CVE-2022-43272HigDec 2, 2022
    affected < 3.6.7-bp154.2.3.1fixed 3.6.7-bp154.2.3.1

    DCMTK v3.6.7 was discovered to contain a memory leak via the T_ASC_Association object.

  • CVE-2022-2121HigJun 24, 2022
    affected < 3.6.7-bp154.2.3.1fixed 3.6.7-bp154.2.3.1

    OFFIS DCMTK's (All versions prior to 3.6.7) has a NULL pointer dereference vulnerability while processing DICOM files, which may result in a denial-of-service condition.

  • CVE-2022-2120HigJun 24, 2022
    affected < 3.6.7-bp154.2.3.1fixed 3.6.7-bp154.2.3.1

    OFFIS DCMTK's (All versions prior to 3.6.7) service class user (SCU) is vulnerable to relative path traversal, allowing an attacker to write DICOM files into arbitrary directories under controlled names. This could allow remote code execution.

  • CVE-2022-2119HigJun 24, 2022
    affected < 3.6.7-bp154.2.3.1fixed 3.6.7-bp154.2.3.1

    OFFIS DCMTK's (All versions prior to 3.6.7) service class provider (SCP) is vulnerable to path traversal, allowing an attacker to write DICOM files into arbitrary directories under controlled names. This could allow remote code execution.