Bug 1223398 (CVE-2024-22373) - VUL-0: CVE-2024-22373: gdcm: out-of-bounds write in the JPEG2000Codec:DecodeByStreamsCommon functionality
Summary: VUL-0: CVE-2024-22373: gdcm: out-of-bounds write in the JPEG2000Codec:DecodeB...
Status: RESOLVED FIXED
Alias: CVE-2024-22373
Product: openSUSE Distribution
Classification: openSUSE
Component: Other (show other bugs)
Version: Leap 15.6
Hardware: Other Other
: P3 - Medium : Major (vote)
Target Milestone: ---
Assignee: Axel Braun
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/403162/
Whiteboard: CVSSv3.1:SUSE:CVE-2024-22373:8.1:(AV:...
Keywords:
Depends on:
Blocks:
 
Reported: 2024-04-25 16:28 UTC by SMASH SMASH
Modified: 2024-06-18 22:04 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description SMASH SMASH 2024-04-25 16:28:30 UTC
An out-of-bounds write vulnerability exists in the JPEG2000Codec::DecodeByStreamsCommon functionality of Mathieu Malaterre Grassroot DICOM 3.0.23. A specially crafted DICOM file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-22373
https://www.cve.org/CVERecord?id=CVE-2024-22373
https://talosintelligence.com/vulnerability_reports/TALOS-2024-1935
https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-1935
Comment 3 Axel Braun 2024-05-14 08:38:35 UTC
3.0.24 should fix this: https://build.opensuse.org/request/show/1173919
Comment 4 Axel Braun 2024-06-14 16:50:29 UTC
3.0.24 is in Factory
Comment 5 Axel Braun 2024-06-14 16:53:09 UTC
3.0.24 is in Factory and mr to Lp155, 156
Comment 6 OBSbugzilla Bot 2024-06-14 17:25:01 UTC
This is an autogenerated message for OBS integration:
This bug (1223398) was mentioned in
https://build.opensuse.org/request/show/1180953 Backports:SLE-15-SP5 / gdcm
https://build.opensuse.org/request/show/1180954 Backports:SLE-15-SP6 / gdcm
Comment 7 Marcus Meissner 2024-06-18 22:04:51 UTC
openSUSE-SU-2024:0167-1: An update that fixes one vulnerability is now available.

Category: security (important)
Bug References: 1223398
CVE References: CVE-2024-22373
JIRA References: 
Sources used:
openSUSE Backports SLE-15-SP5 (src):    gdcm-3.0.24-bp155.2.4.1