UBUNTU-CVE-2024-47796

Source
https://ubuntu.com/security/CVE-2024-47796
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-47796.json
JSON Data
https://api.test.osv.dev/v1/vulns/UBUNTU-CVE-2024-47796
Related
Published
2025-01-13T15:15:00Z
Modified
2025-01-17T08:22:04Z
Summary
[none]
Details

An improper array index validation vulnerability exists in the nowindow functionality of OFFIS DCMTK 3.6.8. A specially crafted DICOM file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability.

References

Affected packages

Ubuntu:Pro:16.04:LTS / dcmtk

Package

Name
dcmtk
Purl
pkg:deb/ubuntu/dcmtk@3.6.1~20150924-5ubuntu0.1~esm2?arch=source&distro=esm-apps/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*

3.6.0-15.1
3.6.1~20150629-5
3.6.1~20150924-4
3.6.1~20150924-5
3.6.1~20150924-5ubuntu0.1~esm1
3.6.1~20150924-5ubuntu0.1~esm2

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:18.04:LTS / dcmtk

Package

Name
dcmtk
Purl
pkg:deb/ubuntu/dcmtk@3.6.2-3ubuntu0.1~esm2?arch=source&distro=esm-apps/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*

3.6.2-2
3.6.2-2build1
3.6.2-3
3.6.2-3build1
3.6.2-3build2
3.6.2-3build3
3.6.2-3ubuntu0.1~esm1
3.6.2-3ubuntu0.1~esm2

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:20.04:LTS / dcmtk

Package

Name
dcmtk
Purl
pkg:deb/ubuntu/dcmtk@3.6.4-2.1ubuntu0.1?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*

3.6.4-2.1
3.6.4-2.1build1
3.6.4-2.1build2
3.6.4-2.1ubuntu0.1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:22.04:LTS / dcmtk

Package

Name
dcmtk
Purl
pkg:deb/ubuntu/dcmtk@3.6.6-5?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*

3.6.5-1
3.6.6-3ubuntu1
3.6.6-3ubuntu2
3.6.6-4
3.6.6-5

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.10 / dcmtk

Package

Name
dcmtk
Purl
pkg:deb/ubuntu/dcmtk@3.6.8-6?arch=source&distro=oracular

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*

3.6.7-9.1build4
3.6.7-13
3.6.7-15
3.6.8-5ubuntu2
3.6.8-6

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.04:LTS / dcmtk

Package

Name
dcmtk
Purl
pkg:deb/ubuntu/dcmtk@3.6.7-9.1build4?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*

3.6.7-9
3.6.7-9.1build2
3.6.7-9.1build3
3.6.7-9.1build4

Ecosystem specific

{
    "ubuntu_priority": "medium"
}