V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2015-8396
DEB
CriticalConfirmedExploit available

Integer overflow in the ImageRegionReader::ReadIntoBuffer function in MediaStorageAndFileFormat/gdcmImageRegionReader.cxx in Grassroots DIC…

CVSS
10.0
Critical
EPSS
0.17
p96
Published
2015-01-01
Updated
2015-01-01
Description

Integer overflow in the ImageRegionReader::ReadIntoBuffer function in MediaStorageAndFileFormat/gdcmImageRegionReader.cxx in Grassroots DICOM (aka GDCM) before 2.6.2 allows attackers to execute arbitrary code via crafted header dimensions in a DICOM image file, which triggers a buffer overflow.

Tags · CWE
Pre-auth
CWE-189
Affected products
GdcmGdcmGdcmGdcmGdcmGdcmGdcmGdcmGdcmGdcmGdcmGdcmGdcmGdcmGdcmGdcmGdcmGdcmGdcmGdcm
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Timeline
2015-01-01
Published
2015-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: C
Changed (C)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.168 · p96
Known exploited (KEV)
No
Known exploits — Сканер-ВС
39229
exploitdb · https://www.exploit-db.com/exploits/39229
Enterprise
Affected products
ProductVendorStatus
gdcmTracked
gdcmTracked
gdcmTracked
gdcmTracked
gdcmTracked
gdcmTracked
gdcmTracked
gdcmTracked
gdcmTracked
gdcmTracked
gdcmTracked
gdcmTracked
gdcmTracked
gdcmTracked
gdcmTracked
gdcmTracked
gdcmTracked
gdcmTracked
gdcmTracked
gdcmTracked
Showing first 20 of 21
Source databases
DEB
CVE
UBU