CVE-2022-2121: OFFIS DCMTK NULL Pointer Dereference
Published Jun 24, 2022
·Updated
Last updated 17 September 2024
Other sources
OFFIS DCMTK's (All versions prior to 3.6.7) has a NULL pointer dereference vulnerability while processing DICOM files, which may result in a denial-of-service condition.
Affected Software
2 affected componentsFixes available
debian/dcmtk<=3.6.5-1
3.6.7-9~deb12u13.6.8-6
OFFIS DCMTK<3.6.7
Event History
Jun 24, 2022
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Sep 21, 2024
Data Sourced
via Ubuntu·10:10 AM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Launchpad·10:11 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-2121?
CVE-2022-2121 is classified as a denial-of-service vulnerability due to a NULL pointer dereference in OFFIS DCMTK.
2
How do I fix CVE-2022-2121?
To fix CVE-2022-2121, upgrade OFFIS DCMTK to version 3.6.7 or later.
3
Which versions of OFFIS DCMTK are affected by CVE-2022-2121?
All versions of OFFIS DCMTK prior to 3.6.7 are affected by CVE-2022-2121.
4
Does CVE-2022-2121 affect Debian packages?
Yes, Debian packages of dcmtk are affected if they are below version 3.6.7-9~deb12u1 or 3.6.8-6.
5
What could be the impact of CVE-2022-2121 on systems?
The exploit of CVE-2022-2121 may lead to a denial-of-service condition on systems processing DICOM files.