CVE-2024-28130: Incorrect Type Cast
Published Apr 23, 2024
·Updated
An incorrect type conversion vulnerability exists in the DVPSSoftcopyVOIPList::createFromImage functionality of OFFIS DCMTK 3.6.8. A specially crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
Affected Software
3 affected componentsFixes available
debian/dcmtk<=3.6.5-1, <=3.6.7-9~deb12u1
3.6.8-6
OFFIS DCMTK=3.6.8
Debian Debian Linux=10.0
Event History
Apr 23, 2024
CVE Published
via MITRE·02:46 PM
Data Sourced
via MITRE·02:46 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
Affected Software
Sep 21, 2024
Data Sourced
via Ubuntu·10:10 AM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Launchpad·10:11 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-28130?
CVE-2024-28130 is considered a critical vulnerability due to its potential for arbitrary code execution.
2
How do I fix CVE-2024-28130?
To fix CVE-2024-28130, update your DCMTK package to version 3.6.8-6 or later.
3
What systems are affected by CVE-2024-28130?
CVE-2024-28130 affects versions of the OFFIS DCMTK software prior to 3.6.8-6.
4
What type of attack does CVE-2024-28130 enable?
CVE-2024-28130 enables attackers to execute arbitrary code through specially crafted malformed files.
5
Who can exploit CVE-2024-28130?
Any attacker with the ability to provide a malicious file can exploit CVE-2024-28130.