vendor:
Horos
by:
Gjoko 'LiquidWorm' Krstic
7.5
CVSS
HIGH
Remote Memory Overflow
122
CWE
Product Name: Horos
Affected Version From: 2.1.2000
Affected Version To: 2.1.2000
Patch Exists: NO
Related CWE:
CPE: a:horos_project:horos:2.1.0
Platforms Tested: OS X 10.12.2 (Sierra), OS X 10.12.1 (Sierra)
2016
Horos 2.1.0 DICOM Medical Image Viewer Remote Memory Overflow Vulnerability
The vulnerability is caused due to the usage of vulnerable collection of libraries that are part of DCMTK Toolkit, specifically the parser for the DICOM Upper Layer Protocol or DUL. Stack/Heap Buffer overflow/underflow can be triggered when sending and processing wrong length of ACSE data structure received over the network by the DICOM Store-SCP service. An attacker can overflow the stack and the heap of the process when sending large array of bytes to the presentation context item length segment of the DICOM standard, potentially resulting in remote code execution and/or denial of service scenario.
Mitigation:
No official patch or mitigation available