Bugzilla – Bug 1223401
VUL-0: CVE-2024-25569: gdcm: out-of-bounds read in the RAWCodec:DecodeBytes functionality
Last modified: 2024-06-14 16:54:15 UTC
An out-of-bounds read vulnerability exists in the RAWCodec::DecodeBytes functionality of Mathieu Malaterre Grassroot DICOM 3.0.23. A specially crafted DICOM file can lead to an out-of-bounds read. An attacker can provide a malicious file to trigger this vulnerability. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-25569 https://www.cve.org/CVERecord?id=CVE-2024-25569 https://talosintelligence.com/vulnerability_reports/TALOS-2024-1944 https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-1944
3.0.24 should fix this: https://build.opensuse.org/request/show/1173919
3.0.34 is in Factory an mr to LP155, 156