GHSA-562h-465j-vfp9HighCVSS 8.1
An out-of-bounds write vulnerability exists in the JPEG2000Codec::DecodeByStreamsCommon...
🔗 CVE IDs covered (1)
📋 Description
An out-of-bounds write vulnerability exists in the JPEG2000Codec::DecodeByStreamsCommon functionality of Mathieu Malaterre Grassroot DICOM 3.0.23. A specially crafted DICOM file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
🔗 References (8)
- https://nvd.nist.gov/vuln/detail/CVE-2024-22373
- https://talosintelligence.com/vulnerability_reports/TALOS-2024-1935
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-1935
- https://lists.fedoraproject.org/archives/list/[email protected]/message/BZJ4IG7EXMSMPHTK5ZFASCW6MHSOVZOE
- https://lists.fedoraproject.org/archives/list/[email protected]/message/N5HXUKUJ7SG3TK456SGUWVZ4Z5D7JKOL
- https://lists.fedoraproject.org/archives/list/[email protected]/message/WJA7QWWZWMY4AQFR35EA7S3CFVUTOQYG
- http://www.openwall.com/lists/oss-security/2026/09/10/13
- https://github.com/advisories/GHSA-562h-465j-vfp9