First published: Thu Oct 19 2023(Updated: )
Sante DICOM Viewer Pro lacks proper validation of user-supplied data when parsing DICOM files. This could lead to a stack-based buffer overflow. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process.
Credit: ics-cert@hq.dhs.gov ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Santesoft Dicom Viewer Pro | <12.2.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-35986 is a vulnerability in Sante DICOM Viewer Pro that allows an attacker to execute arbitrary code.
CVE-2023-35986 allows an attacker to execute arbitrary code in the context of the current process in Sante DICOM Viewer Pro.
CVE-2023-35986 has a severity rating of 7.8 (high).
To fix CVE-2023-35986 in Sante DICOM Viewer Pro, update to version 12.2.7 or later.
For more information about CVE-2023-35986, refer to the official advisory from CISA: <a href="https://www.cisa.gov/news-events/ics-medical-advisories/icsma-23-285-01">https://www.cisa.gov/news-events/ics-medical-advisories/icsma-23-285-01</a>.