在 DCMTK 3.7.0 及更早版本中,ConcatenationLoader 存在堆溢出读取漏洞。该漏洞源于在复制像素数据帧时,未将 PixelData 缓冲区的实际长度与声明的 NumberOfFrames 进行匹配验证。攻击者可构造恶意的 DICOM 实例,使其声明的帧数多于缓冲区中实际包含的帧数,从而触发堆溢出读取,导致应用程序崩溃或泄露相邻的堆内存数据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet