7.5
CVSSv3

CVE-2024-28130

Published: 23/04/2024 Updated: 24/04/2024
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

An incorrect type conversion vulnerability exists in the DVPSSoftcopyVOI_PList::createFromImage functionality of OFFIS DCMTK 3.6.8. A specially crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

Vendor Advisories

Debian Bug report logs - #1070207 dcmtk: CVE-2024-28130 Package: src:dcmtk; Maintainer for src:dcmtk is Debian Med Packaging Team <debian-med-packaging@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 1 May 2024 20:03:02 UTC Severity: important Tags: security, upstream Foun ...