[SYSS-2026-070]: GDCM (Grassroots DICOM) - Integer Overflow (CWE-190)
SySS disclosed unpatched high-risk integer overflow SYSS-2026-070 in GDCM 3.3.0, with no CVE.
SySS advisory SYSS-2026-070 reports an integer overflow (CWE-190) in GDCM (Grassroots DICOM) version 3.3.0. The lab rates the risk high and lists the solution status as open. The manufacturer was notified on 2026-07-24, with public disclosure on 2026-09-23. No CVE is assigned and the text does not claim exploitation in the wild.
- Integer overflow (CWE-190) tracked as SYSS-2026-070.
- Affects GDCM 3.3.0; tested on that version.
- SySS rates the risk high and the fix status open.
- No CVE identifier has been assigned.
- Public disclosure date is 2026-09-23.
Posted by Matthias Deeg via Fulldisclosure on Sep 26 Advisory ID: SYSS-2026-070 Product: GDCM (Grassroots DICOM) Manufacturer: GDCM Project Affected Version(s): 3.3.0 Tested Version(s): 3.3.0 Vulnerability Type: Integer Overflow (CWE-190) Risk Level: High Solution Status: Open Manufacturer Notification: 2026-07-24 Public Disclosure: 2026-09-23 CVE Reference: Not yet assigned Author of...
This source does not provide full text. Read it at seclists.org.