VDB

CVE-2021-41688

CVE-2021-41688 PUBLISHED CVSS 7.5 HIGH

DCMTK through 3.6.6 does not handle memory free properly. The object in the program is free but its address is still used in other locations. Sending specific requests to the dcmqrdb program will incur a double free. An attacker can use it to launch a DoS attack.

EPSS 1.74% · 76.1th percentile

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
1.74%
76.1th percentile

Affected Products

VendorProductVersions
n/an/an/a
offisdcmtk0

Timeline

  • Jun 28, 2022 CVE Published
  • Jun 29, 2022 EPSS Score
  • Jul 6, 2022 CVE Updated
  • Aug 17, 2022 EPSS Score
  • Oct 3, 2022 EPSS Score
  • Nov 20, 2022 EPSS Score
  • Jan 7, 2023 EPSS Score
  • Feb 24, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 12, 2023 EPSS Score
  • Jul 17, 2023 EPSS Score
  • Sep 3, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›