VDB

CVE-2021-41689

CVE-2021-41689 PUBLISHED CVSS 5 MEDIUM

DCMTK through 3.6.6 does not handle string copy properly. Sending specific requests to the dcmqrdb program, it would query its database and copy the result even if the result is null, which can incur a head-based overflow. An attacker can use it to launch a DoS attack.

EPSS 0.11% · 29.0th percentile

Risk Scores

CVSS 2.0
5
EPSS Score
0.11%
29.0th percentile

Affected Products

VendorProductVersions
offisdcmtk0
dcmtkdcmtk0
n/an/an/a

Timeline

  • Jun 28, 2022 CVE Published
  • Jun 29, 2022 EPSS Score
  • Jul 6, 2022 CVE Updated
  • Aug 17, 2022 EPSS Score
  • Oct 3, 2022 EPSS Score
  • Nov 20, 2022 EPSS Score
  • Jan 6, 2023 EPSS Score
  • Feb 23, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 12, 2023 EPSS Score
  • May 29, 2023 EPSS Score
  • Jul 16, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›