[SYSS-2026-071]: GDCM (Grassroots DICOM) - Format String (CWE-134)
SySS disclosed an unpatched medium-risk format-string flaw in GDCM 3.3.0, with no CVE assigned.
SySS published advisory SYSS-2026-071 describing a format-string vulnerability (CWE-134) in GDCM (Grassroots DICOM) 3.3.0, the tested version. Risk is rated medium and the solution status is open, so no fix is listed. The vendor was notified on 2026-07-24 and the issue was disclosed on 2026-09-23. No CVE has been assigned and exploitation is not reported.
- Format-string flaw (CWE-134) in GDCM 3.3.0.
- SySS rates risk as medium.
- No fix; solution status remains open.
- No CVE has been assigned yet.
- Vendor was notified on 2026-07-24.
Posted by Matthias Deeg via Fulldisclosure on Sep 26 Advisory ID: SYSS-2026-071 Product: GDCM (Grassroots DICOM) Manufacturer: GDCM Project Affected Version(s): 3.3.0 Tested Version(s): 3.3.0 Vulnerability Type: Format String (CWE-134) Risk Level: Medium Solution Status: Open Manufacturer Notification: 2026-07-24 Public Disclosure: 2026-09-23 CVE Reference: Not yet assigned Author of...
This source does not provide full text. Read it at seclists.org.