Name | CVE-2015-8979 |
Description | Stack-based buffer overflow in the parsePresentationContext function in storescp in DICOM dcmtk-3.6.0 and earlier allows remote attackers to cause a denial of service (segmentation fault) via a long string sent to TCP port 4242. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more) |
References | DLA-755-1, DSA-3749-1 |
NVD severity | medium |
Debian Bugs | 848830 |
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|---|---|---|
dcmtk (PTS) | stretch | 3.6.1~20160216-4 | fixed |
buster | 3.6.4-2.1 | fixed | |
bullseye | 3.6.5-1 | fixed | |
bookworm | 3.6.6-5 | fixed | |
sid | 3.6.7-1 | fixed |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
dcmtk | source | wheezy | 3.6.0-12+deb7u1 | DLA-755-1 | ||
dcmtk | source | jessie | 3.6.0-15+deb8u1 | DSA-3749-1 | ||
dcmtk | source | (unstable) | 3.6.1~20160216-2 | 848830 |
3.6.1~20160216-2 is the first version in unstable containing the fix
http://zeroscience.mk/en/vulnerabilities/ZSL-2016-5384.php
Fixed by: https://github.com/commontk/DCMTK/commit/1b6bb76
https://www.openwall.com/lists/oss-security/2016/12/17/2