DCMTK through 3.6.6 does not handle string copy properly. Sending specific requests to the dcmqrdb program, it would query its database and copy the result even if the result is null, which can incur a head-based overflow. An attacker can use it to launch a DoS attack.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2022-06-28T09:38:17

Updated: 2024-08-04T03:15:29.267Z

Reserved: 2021-09-27T00:00:00

Link: CVE-2021-41689

cve-icon Vulnrichment

Updated: 2024-08-04T03:15:29.267Z

cve-icon NVD

Status : Modified

Published: 2022-06-28T13:15:10.587

Modified: 2024-08-01T13:42:23.660

Link: CVE-2021-41689

cve-icon Redhat

No data.