CVE-2015-8396: Buffer Overflow
Integer overflow in the ImageRegionReader::ReadIntoBuffer function in MediaStorageAndFileFormat/gdcmImageRegionReader.cxx in Grassroots DICOM (aka GDCM) before 2.6.2 allows attackers to execute arbitrary code via crafted header dimensions in a DICOM image file, which triggers a buffer overflow.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-8396?
CVE-2015-8396 has a critical severity rating due to its potential to allow arbitrary code execution.
How do I fix CVE-2015-8396?
To fix CVE-2015-8396, update Grassroots DICOM to version 2.6.2 or later.
What vulnerabilities does CVE-2015-8396 exploit?
CVE-2015-8396 exploits an integer overflow that leads to a buffer overflow in the ImageRegionReader function.
What software is affected by CVE-2015-8396?
CVE-2015-8396 affects Grassroots DICOM versions prior to 2.6.2, specifically 2.6.0 and 2.6.1.
Can CVE-2015-8396 be exploited remotely?
Yes, CVE-2015-8396 can potentially be exploited remotely through crafted DICOM image files.