VDB
CVE-2024-52333
CVE-2024-52333
PUBLISHED
CVSS 8.399999618530273 HIGH
An improper array index validation vulnerability exists in the determineMinMax functionality of OFFIS DCMTK 3.6.8. A specially crafted DICOM file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability.
EPSS 0.10% · 27.4th percentile
Risk Scores
CVSS 3.1
8.399999618530273
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.10%
27.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| OFFIS | DCMTK | 3.6.8 |
| offis | dcmtk | 3.6.8 |
Timeline
- Jan 13, 2025 CVE Published
- Jan 13, 2025 PoC Published
- Jan 13, 2025 PoC Published
- Jan 13, 2025 PoC Published
- Jan 13, 2025 PoC Published
- Jan 13, 2025 PoC Published
- Jan 13, 2025 PoC Published
- Jan 14, 2025 EPSS Score
- Jan 30, 2025 EPSS Score
- Feb 14, 2025 EPSS Score
- Mar 2, 2025 EPSS Score
- Mar 17, 2025 EPSS Score
References
- https://talosintelligence.com/vulnerability_reports/TALOS-2024-2121 url
- https://git.dcmtk.org/?p=dcmtk.git;a=commit;h=03e851b0586d05057c3268988e180ffb426b2e03 url
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2121 url
- https://lists.debian.org/debian-lts-announce/2025/01/msg00032.html url
- https://nvd.nist.gov/vuln/detail/CVE-2024-52333 advisory