7.2
CVSSv2

CVE-2013-6825

Published: 10/06/2014 Updated: 07/11/2023
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

(1) movescu.cc and (2) storescp.cc in dcmnet/apps/, (3) dcmnet/libsrc/scp.cc, (4) dcmwlm/libsrc/wlmactmg.cc, (5) dcmprscp.cc and (6) dcmpsrcv.cc in dcmpstat/apps/, (7) dcmpstat/tests/msgserv.cc, and (8) dcmqrdb/apps/dcmqrscp.cc in DCMTK 3.6.1 and previous versions does not check the return value of the setuid system call, which allows local users to gain privileges by creating a large number of processes.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

offis dcmtk 3.5.4

offis dcmtk 3.5.3

offis dcmtk 3.6.0

offis dcmtk

offis dcmtk 3.5.2a

offis dcmtk 3.5.1

offis dcmtk 3.5.2