CVE-2024-29421

NameCVE-2024-29421
Descriptionxmedcon 0.23.0 and fixed in v.0.24.0 is vulnerable to Buffer Overflow via libs/dicom/basic.c which allows an attacker to execute arbitrary code.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1077369

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
xmedcon (PTS)bullseye0.16.3+dfsg-1+deb11u1fixed
bookworm0.23.0-gtk3+dfsg-1+deb12u1fixed
sid, trixie0.24.0-gtk3+dfsg-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
xmedconsourcebullseye0.16.3+dfsg-1+deb11u1
xmedconsourcebookworm0.23.0-gtk3+dfsg-1+deb12u1
xmedconsource(unstable)0.24.0-gtk3+dfsg-11077369

Notes

https://github.com/SpikeReply/advisories/blob/530dbd7ce68600a22c47dd1bcbe360220feda1d9/cve/xmedcon/cve-2024-29421.md

Search for package or bug name: Reporting problems