CVE-2024-34509: Medium severity debian/dcmtk vulnerability
Published May 5, 2024
·Updated
dcmdata in DCMTK before 3.6.9 has a segmentation fault via an invalid DIMSE message.
Affected Software
3 affected componentsFixes available
debian/dcmtk<=3.6.5-1, <=3.6.7-9~deb12u1
3.6.8-6
OFFIS DCMTK<3.6.9
Debian Debian Linux=10.0
Remediation
Event History
May 5, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 PM
Description
Data Sourced
via NVD·08:15 PM
RemedySeverityAffected Software
Sep 21, 2024
Data Sourced
via Ubuntu·10:10 AM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Launchpad·10:11 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-34509?
CVE-2024-34509 is classified as a critical vulnerability due to the potential for a segmentation fault that can lead to application crashes.
2
How do I fix CVE-2024-34509?
To remediate CVE-2024-34509, update dcmtk to version 3.6.9 or later, as this version addresses the segmentation fault issue.
3
What versions of DCMTK are affected by CVE-2024-34509?
Versions of DCMTK prior to 3.6.9, specifically versions 3.6.8-6 and below, are affected by CVE-2024-34509.
4
What components are impacted by CVE-2024-34509?
CVE-2024-34509 specifically impacts the dcmdata component in the DCMTK library.
5
Is there any workaround for CVE-2024-34509?
There are no effective workarounds for CVE-2024-34509 other than upgrading to the fixed version.