ZeroHour
oss-securitypublished ()ingested

GDCM <= 3.2.7: six memory-safety and denial-of-service vulnerabilities, no CVE

mediumVulnerabilityimportance 38
AI summary · glm-5.3-flash

Six memory-safety and denial-of-service flaws disclosed in the GDCM DICOM parsing library, affecting versions through 3.2.7.

Researcher Abhinav Agarwal disclosed six vulnerabilities in GDCM (Grassroots DICOM), an open-source C++ library for parsing and processing DICOM files. All six were confirmed against GDCM 3.2.6 using AddressSanitizer and UndefinedBehaviorSanitizer, and source review found the vulnerable patterns through version 3.2.7 and the upstream master snapshot. Potential impacts include heap corruption, process-memory disclosure, stack exhaustion, and process termination in applications parsing untrusted DICOM files. No CVE identifiers have been assigned at the time of disclosure.

  • Confirmed via AddressSanitizer and UndefinedBehaviorSanitizer against GDCM 3.2.6
  • Vulnerable patterns persist through version 3.2.7 and upstream master
  • Impacts include heap corruption, memory disclosure, and stack exhaustion
  • No CVE identifiers assigned at time of disclosure
VendorsGDCM
ProductsGDCM
Full article

Posted by Abhinav Agarwal on Sep 09 I am disclosing six vulnerabilities in GDCM (Grassroots DICOM), an open-source C++ library for parsing and processing DICOM files. I confirmed all six against GDCM 3.2.6 with AddressSanitizer or UndefinedBehaviorSanitizer; source review found the vulnerable patterns through 3.2.7 and in the reviewed upstream master snapshot. Impact includes heap corruption, process-memory disclosure, stack exhaustion, and process termination when an application...

This source does not provide full text. Read it at seclists.org.