CVE-2024-47796

A

n improper array index validation vulnerability exists in the nowindow functionality of OFFIS DCMTK 3.6.8. A specially crafted DICOM file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability.

Configurations

Configuration 1 (hide)

cpe:2.3:a:offis:dcmtk:3.6.8:*:*:*:*:*:*:*

History

03 Nov 2025, 21:16

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2025/01/msg00032.html -

03 Nov 2025, 20:16

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2025/06/msg00025.html -

24 Jun 2025, 13:47

Type Values Removed Values Added
CPE cpe:2.3:a:offis:dcmtk:3.6.8:*:*:*:*:*:*:*
First Time Offis
Offis dcmtk
CPE cpe:2.3:a:offis:dcmtk:3.6.8:*:*:*:*:*:*:*
Summary
  • (es) Existe una vulnerabilidad de validación incorrecta del índice de matriz en la funcionalidad nowindow de OFFIS DCMTK 3.6.8. Un archivo DICOM manipulado especialmente puede provocar una escritura fuera de los límites. Un atacante puede proporcionar un archivo malicioso para activar esta vulnerabilidad.
References () https://git.dcmtk.org/?p=dcmtk.git;a=commit;h=89a6e399f1e17d08a8bc8cdaa05b2ac9a50cd4f6 - () https://git.dcmtk.org/?p=dcmtk.git;a=commit;h=89a6e399f1e17d08a8bc8cdaa05b2ac9a50cd4f6 - Patch
References () https://talosintelligence.com/vulnerability_reports/TALOS-2024-2122 - () https://talosintelligence.com/vulnerability_reports/TALOS-2024-2122 - Exploit, Third Party Advisory
References () https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2122 - () https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2122 - Exploit, Third Party Advisory
References () https://git.dcmtk.org/?p=dcmtk.git;a=commit;h=89a6e399f1e17d08a8bc8cdaa05b2ac9a50cd4f6 - () https://git.dcmtk.org/?p=dcmtk.git;a=commit;h=89a6e399f1e17d08a8bc8cdaa05b2ac9a50cd4f6 - Patch
References () https://talosintelligence.com/vulnerability_reports/TALOS-2024-2122 - () https://talosintelligence.com/vulnerability_reports/TALOS-2024-2122 - Exploit, Third Party Advisory
References () https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2122 - () https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2122 - Exploit, Third Party Advisory
First Time Offis
Offis dcmtk

13 Jan 2025, 16:15

Type Values Removed Values Added
CPE cpe:2.3:a:offis:dcmtk:3.6.8:*:*:*:*:*:*:*
References
  • () https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2122 -
References () https://git.dcmtk.org/?p=dcmtk.git;a=commit;h=89a6e399f1e17d08a8bc8cdaa05b2ac9a50cd4f6 - Patch () https://git.dcmtk.org/?p=dcmtk.git;a=commit;h=89a6e399f1e17d08a8bc8cdaa05b2ac9a50cd4f6 -
References () https://talosintelligence.com/vulnerability_reports/TALOS-2024-2122 - Exploit, Third Party Advisory () https://talosintelligence.com/vulnerability_reports/TALOS-2024-2122 -
References () https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2122 - Exploit, Third Party Advisory () https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2122 -

13 Jan 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-13 15:15

Updated : 2025-11-03 21:16


NVD link : CVE-2024-47796

Mitre link : CVE-2024-47796

CVE.ORG link : CVE-2024-47796


JSON object : View

Products Affected
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer