Id:
CVE-2021-41689
Comment
:
DCMTK through 3.6.6 does not handle string copy properly. Sending specific requests to the dcmqrdb program, it would query its database and copy the result even if the result is null, which can incur a head-based overflow. An attacker can use it to launch a DoS attack.
CVSSv2 Score:
5
Access vector:
|
NETWORK
|
Access complexity:
|
LOW
|
Authentication:
|
NONE
|
Confidentiality impact:
|
NONE
|
Integrity impact:
|
NONE
|
Availability impact:
|
PARTIAL
|
CVSSv2 Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:P
CVSSv3 Score:
7.5
Attack vector:
|
NETWORK
|
Attack complexity:
|
LOW
|
Privileges required:
|
NONE
|
User interaction:
|
NONE
|
Scope:
|
UNCHANGED
|
Confidentiality impact:
|
NONE
|
Integrity impact:
|
NONE
|
Availability impact:
|
HIGH
|
CVSSv3 Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
References: