CVE-2024-52333: Buffer Overflow
Published Jan 13, 2025
·Updated
An improper array index validation vulnerability exists in the determineMinMax functionality of OFFIS DCMTK 3.6.8. A specially crafted DICOM file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability.
Affected Software
2 affected components
OFFIS DCMTK
OFFIS DCMTK=3.6.8
Remediation
Event History
Jan 13, 2025
CVE Published
via MITRE·02:10 PM
Data Sourced
via MITRE·02:10 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-52333?
CVE-2024-52333 has a high severity due to its potential for out-of-bounds writes that can be exploited by attackers.
2
How do I fix CVE-2024-52333?
To fix CVE-2024-52333, update OFFIS DCMTK to the latest version where the vulnerability has been addressed.
3
What products are affected by CVE-2024-52333?
CVE-2024-52333 affects OFFIS DCMTK version 3.6.8 and prior versions.
4
What type of attack can exploit CVE-2024-52333?
CVE-2024-52333 can be exploited by an attacker supplying a specially crafted DICOM file.
5
What is the impact of CVE-2024-52333 on system security?
The impact of CVE-2024-52333 includes potential data corruption or unauthorized access due to out-of-bounds writes.