VDB
CVE-2021-41688
CVE-2021-41688
PUBLISHED
CVSS 7.5 HIGH
DCMTK through 3.6.6 does not handle memory free properly. The object in the program is free but its address is still used in other locations. Sending specific requests to the dcmqrdb program will incur a double free. An attacker can use it to launch a DoS attack.
EPSS 0.14% · 33.8th percentile
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
0.14%
33.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| offis | dcmtk | 0 |
Exploit Intelligence
Timeline
- Jun 28, 2022 CVE Published
- Jun 29, 2022 EPSS Score
- Jul 6, 2022 CVE Updated
- Aug 17, 2022 EPSS Score
- Oct 3, 2022 EPSS Score
- Nov 20, 2022 EPSS Score
- Jan 6, 2023 EPSS Score
- Feb 23, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 12, 2023 EPSS Score
- May 29, 2023 EPSS Score
- Jul 16, 2023 EPSS Score
References
- https://github.com/DCMTK/dcmtk url
- https://github.com/DCMTK/dcmtk/commit/a9697dfeb672b0b9412c00c7d36d801e27ec85cb url
- [debian-lts-announce] 20240628 [SECURITY] [DLA 3847-1] dcmtk security update mailing-list
- https://lists.debian.org/debian-lts-announce/2025/01/msg00032.html url
- https://nvd.nist.gov/vuln/detail/CVE-2021-41688 advisory