VDB

CVE-2021-41687

CVE-2021-41687 PUBLISHED CVSS 7.5 HIGH

DCMTK through 3.6.6 does not handle memory free properly. The program malloc a heap memory for parsing data, but does not free it when error in parsing. Sending specific requests to the dcmqrdb program incur the memory leak. An attacker can use it to launch a DoS attack.

EPSS 0.18% · 39.3th percentile

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
0.18%
39.3th percentile

Affected Products

VendorProductVersions
offisdcmtk0
n/an/an/a

Timeline

  • Jun 28, 2022 CVE Published
  • Jun 29, 2022 EPSS Score
  • Jul 6, 2022 CVE Updated
  • Aug 17, 2022 EPSS Score
  • Oct 3, 2022 EPSS Score
  • Nov 20, 2022 EPSS Score
  • Jan 6, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 12, 2023 EPSS Score
  • May 29, 2023 EPSS Score
  • Jul 16, 2023 EPSS Score
  • Sep 1, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›