CVE-2019-1010228: Buffer Overflow
Last updated 24 July 2024
Other sources
OFFIS.de DCMTK 3.6.3 and below is affected by: Buffer Overflow. The impact is: Possible code execution and confirmed Denial of Service. The component is: DcmRLEDecoder::decompress() (file dcrledec.h, line 122). The attack vector is: Many scenarios of DICOM file processing (e.g. DICOM to image conversion). The fixed version is: 3.6.4, after commit 40917614e.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-1010228?
CVE-2019-1010228 has a severity rating that indicates possible code execution and confirmed denial of service.
How do I fix CVE-2019-1010228?
To fix CVE-2019-1010228, update to versions DCMTK 3.6.5-1, 3.6.7-9~deb12u1, or 3.6.8-6.
What components are affected by CVE-2019-1010228?
The affected component is DcmRLEDecoder::decompress() in DCMTK versions 3.6.3 and below.
What are the attack vectors for CVE-2019-1010228?
CVE-2019-1010228 can be exploited through many scenarios of DICOM file processing.
What software is affected by CVE-2019-1010228?
CVE-2019-1010228 affects OFFIS DCMTK versions up to and including 3.6.3, and certain Fedora releases.