VDB
CVE-2021-41687
CVE-2021-41687
PUBLISHED
CVSS 7.5 HIGH
DCMTK through 3.6.6 does not handle memory free properly. The program malloc a heap memory for parsing data, but does not free it when error in parsing. Sending specific requests to the dcmqrdb program incur the memory leak. An attacker can use it to launch a DoS attack.
EPSS 1.74% · 76.1th percentile
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
1.74%
76.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| offis | dcmtk | 0 |
| n/a | n/a | n/a |
Timeline
- Jun 28, 2022 CVE Published
- Jun 29, 2022 EPSS Score
- Jul 6, 2022 CVE Updated
- Aug 17, 2022 EPSS Score
- Oct 3, 2022 EPSS Score
- Nov 20, 2022 EPSS Score
- Feb 24, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 12, 2023 EPSS Score
- May 30, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Sep 3, 2023 EPSS Score
References
- https://github.com/DCMTK/dcmtk url
- [debian-lts-announce] 20240628 [SECURITY] [DLA 3847-1] dcmtk security update mailing-list
- https://github.com/DCMTK/dcmtk/commit/a9697dfeb672b0b9412c00c7d36d801e27ec85cb url
- https://lists.debian.org/debian-lts-announce/2025/01/msg00032.html url
- https://nvd.nist.gov/vuln/detail/CVE-2021-41687 advisory