vendor:
ConQuest DICOM Server
by:
University of Manchester, Marcel van Herk, Lambert Zijp and Jan Meinders, The Netherlands Cancer Institute
7,5
CVSS
HIGH
Stack/Heap Buffer Overflow/Underflow
119
CWE
Product Name: ConQuest DICOM Server
Affected Version From: 1.4.17d
Affected Version To: 1.4.19beta3b
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2020
ConQuest DICOM Server 1.4.17d Remote Stack Buffer Overflow RCE
A full featured DICOM server has been developed based on the public domain UCDMC DICOM code. The vulnerability is caused due to the usage of vulnerable collection of libraries that are part of DCMTK Toolkit, specifically the parser for the DICOM Upper Layer Protocol or DUL. Stack/Heap Buffer overflow/underflow can be triggered when sending and processing wrong length of ACSE data structure received over the network by the DICOM Store-SCP service. An attacker can overflow the stack and the heap of the process when sending large array of bytes to the presentation context item length segment of the DICOM standard, potentially resulting in remote code execution and/or denial of service scenario.
Mitigation:
Upgrade to the latest version of ConQuest DICOM Server.