SB2024022042 - Multiple vulnerabilities in Imaging Data Commons libdicom
Published: February 20, 2024
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 vulnerabilities.
1) Use-after-free (CVE-ID: CVE-2024-24793)
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error in the DICOM Element Parsing as implemented within the parse_meta_element_create() function. A remote attacker can use a specially crafted DICOM file and execute arbitrary code on the target system.
2) Use-after-free (CVE-ID: CVE-2024-24794)
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error in the DICOM Element Parsing as implemented within the parse_meta_sequence_end() function. A remote attacker can use a specially crafted DICOM file and execute arbitrary code on the target system.
Remediation
Install update from vendor's website.