|
Brought to you by:
Suppliers of:
|
|
|
| |
| A vulnerability in DevIL DICOM "GetUID()" can be exploited by a malicious party to compromise an application using the library. |
| |
Credit:
The information has been provided by Stefan Cornelius.
The original article can be found at: http://secunia.com/secunia_research/2009-51/
|
| |
Vulnerable Systems:
* DevIL 1.7.8 and prior
The vulnerability is caused by a boundary error within the "GetUID()" function in src-IL/src/il_dicom.c. This can be exploited to cause a stack-based buffer overflow by e.g. tricking a user into opening a specially crafted DICOM file in an application using the library.
The vulnerability is confirmed in version 1.7.8. Other versions may also be affected.
Workaround
Do not open untrusted DICOM files.
CVE Information:
CVE-2009-3994
Disclosure Timeline:
27/11/2009 - Vendor and vendor-sec notified.
03/12/2009 - Vendor response.
04/12/2009 - Public disclosure.
|
|
|
|
|