Vulnerabilities > CVE-2015-8396 - Numeric Errors vulnerability in Grassroots Dicom Project Grassroots Dicom 2.6.0/2.6.1

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
grassroots-dicom-project
CWE-189
critical
nessus
exploit available

Summary

Integer overflow in the ImageRegionReader::ReadIntoBuffer function in MediaStorageAndFileFormat/gdcmImageRegionReader.cxx in Grassroots DICOM (aka GDCM) before 2.6.2 allows attackers to execute arbitrary code via crafted header dimensions in a DICOM image file, which triggers a buffer overflow.

Common Weakness Enumeration (CWE)

Exploit-Db

descriptionGrassroots DICOM (GDCM) 2.6.0 and 2.6.1 - ImageRegionReader::ReadIntoBuffer Buffer Overflow. CVE-2015-8396. Dos exploit for linux platform
fileexploits/linux/dos/39229.cpp
idEDB-ID:39229
last seen2016-02-04
modified2016-01-12
platformlinux
port
published2016-01-12
reporterStelios Tsampas
sourcehttps://www.exploit-db.com/download/39229/
titleGrassroots DICOM GDCM 2.6.0 and 2.6.1 - ImageRegionReader::ReadIntoBuffer Buffer Overflow
typedos

Nessus

NASL familyFreeBSD Local Security Checks
NASL idFREEBSD_PKG_E00D8B94C88A11E5B5FE002590263BF5.NASL
descriptionCENSUS S.A. reports : GDCM versions 2.6.0 and 2.6.1 (and possibly previous versions) are prone to an integer overflow vulnerability which leads to a buffer overflow and potentially to remote code execution. GDCM versions 2.6.0 and 2.6.1 (and possibly previous versions) are prone to an out-of-bounds read vulnerability due to missing checks.
last seen2020-06-01
modified2020-06-02
plugin id88504
published2016-02-01
reporterThis script is Copyright (C) 2016-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
sourcehttps://www.tenable.com/plugins/nessus/88504
titleFreeBSD : gdcm -- multiple vulnerabilities (e00d8b94-c88a-11e5-b5fe-002590263bf5)