When MC_Open_Association() function is used to open DICOM Association and gets DICOM Application Context Name with illegal characters, it might result in an unhandled exception.
No analysis available yet.
Vendor Solution
The issue is resolved in Merge DICOM Toolkit 5.18.0 release.
Vendor Workaround
The vulnerability can be exploited by unauthenticated attackers with a privileged position in the network. As a temporary solution, until a patch is released, it is highly recommended do not expose the vulnerable component inside an untrusted network.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-21344 | Use of Externally-Controlled Format String vulnerability in Merge DICOM Toolkit C/C++ on Windows. When MC_Open_Association() function is used to open DICOM Association and gets DICOM Application Context Name with illegal characters, it might result in an unhandled exception. |
No history.
Subscriptions
No data.
Status: PUBLISHED
Assigner: Nozomi
Published:
Updated: 2024-08-01T23:13:08.679Z
Reserved: 2024-01-23T15:02:55.722Z
Link: CVE-2024-23914
Updated: 2024-08-01T23:13:08.679Z
Status : Awaiting Analysis
Published: 2024-05-03T09:15:08.090
Modified: 2024-11-21T08:58:42.020
Link: CVE-2024-23914
No data.
OpenCVE Enrichment
No data.
EUVD