VDB
CVE-2021-41689
CVE-2021-41689
PUBLISHED
CVSS 5 MEDIUM
DCMTK through 3.6.6 does not handle string copy properly. Sending specific requests to the dcmqrdb program, it would query its database and copy the result even if the result is null, which can incur a head-based overflow. An attacker can use it to launch a DoS attack.
EPSS 0.11% · 29.0th percentile
Risk Scores
CVSS 2.0
5
EPSS Score
0.11%
29.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| offis | dcmtk | 0 |
| dcmtk | dcmtk | 0 |
| n/a | n/a | n/a |
Exploit Intelligence
Timeline
- Jun 28, 2022 CVE Published
- Jun 29, 2022 EPSS Score
- Jul 6, 2022 CVE Updated
- Aug 17, 2022 EPSS Score
- Oct 3, 2022 EPSS Score
- Nov 20, 2022 EPSS Score
- Jan 6, 2023 EPSS Score
- Feb 23, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 12, 2023 EPSS Score
- May 29, 2023 EPSS Score
- Jul 16, 2023 EPSS Score
References
- https://github.com/DCMTK/dcmtk url
- https://github.com/DCMTK/dcmtk/commit/5c14bf53fb42ceca12bbcc0016e8704b1580920d url
- [debian-lts-announce] 20240628 [SECURITY] [DLA 3847-1] dcmtk security update mailing-list
- https://lists.debian.org/debian-lts-announce/2025/01/msg00032.html url
- https://nvd.nist.gov/vuln/detail/CVE-2021-41689 advisory