Vulnerability Name: | CVE-2015-8979 (CCN-130495) | ||||||||||||||||||||||||||||||||||||||||||||
Assigned: | 2016-12-16 | ||||||||||||||||||||||||||||||||||||||||||||
Published: | 2016-12-16 | ||||||||||||||||||||||||||||||||||||||||||||
Updated: | 2017-02-23 | ||||||||||||||||||||||||||||||||||||||||||||
Summary: | Stack-based buffer overflow in the parsePresentationContext function in storescp in DICOM dcmtk-3.6.0 and earlier allows remote attackers to cause a denial of service (segmentation fault) via a long string sent to TCP port 4242. | ||||||||||||||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) 6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
6.5 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
| ||||||||||||||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-119 | ||||||||||||||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||||||||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2015-8979 Source: MISC Type: Exploit, Third Party Advisory, VDB Entry http://packetstormsecurity.com/files/140191/DCMTK-storescp-DICOM-storage-C-STORE-SCP-Remote-Stack-Buffer-Overflow.html Source: CCN Type: DICOM Web site dcmtk Source: DEBIAN Type: Third Party Advisory DSA-3749 Source: MLIST Type: Mailing List, Patch, Third Party Advisory [oss-security] 20161217 Re: CVE request - DCMTK remote stack buffer overflow Source: BID Type: Third Party Advisory, VDB Entry 94951 Source: CCN Type: BID-94951 DCMTK CVE-2015-8979 Stack Buffer Overflow Vulnerability Source: MISC Type: Exploit, Technical Description, Third Party Advisory, VDB Entry http://www.zeroscience.mk/en/vulnerabilities/ZSL-2016-5384.php Source: CONFIRM Type: Issue Tracking, Patch, Third Party Advisory, VDB Entry https://bugzilla.redhat.com/show_bug.cgi?id=1405919 Source: XF Type: UNKNOWN dicom-cve20158979-dos(130495) Source: CCN Type: Packet Storm Security [12-16-2016] DCMTK storescp DICOM storage (C-STORE) SCP Remote Stack Buffer Overflow | ||||||||||||||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: ![]() | ||||||||||||||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||||||
BACK |