CVE Vulnerabilities

CVE-2013-6825

Published: Jun 10, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

(1) movescu.cc and (2) storescp.cc in dcmnet/apps/, (3) dcmnet/libsrc/scp.cc, (4) dcmwlm/libsrc/wlmactmg.cc, (5) dcmprscp.cc and (6) dcmpsrcv.cc in dcmpstat/apps/, (7) dcmpstat/tests/msgserv.cc, and (8) dcmqrdb/apps/dcmqrscp.cc in DCMTK 3.6.1 and earlier does not check the return value of the setuid system call, which allows local users to gain privileges by creating a large number of processes.

Affected Software

NameVendorStart VersionEnd Version
DcmtkOffis*3.6.1 (including)
DcmtkOffis3.5.1 (including)3.5.1 (including)
DcmtkOffis3.5.2 (including)3.5.2 (including)
DcmtkOffis3.5.2a (including)3.5.2a (including)
DcmtkOffis3.5.3 (including)3.5.3 (including)
DcmtkOffis3.5.4 (including)3.5.4 (including)
DcmtkOffis3.6.0 (including)3.6.0 (including)
DcmtkUbuntuartful*
DcmtkUbuntucosmic*
DcmtkUbuntudevel*
DcmtkUbuntudisco*
DcmtkUbuntueoan*
DcmtkUbuntuesm-apps/noble*
DcmtkUbuntugroovy*
DcmtkUbuntuhirsute*
DcmtkUbuntuimpish*
DcmtkUbuntulucid*
DcmtkUbuntulunar*
DcmtkUbuntumantic*
DcmtkUbuntunoble*
DcmtkUbuntuoracular*
DcmtkUbuntuplucky*
DcmtkUbuntuprecise*
DcmtkUbuntuquesting*
DcmtkUbuntusaucy*
DcmtkUbuntutrusty*
DcmtkUbuntuupstream*
DcmtkUbuntuutopic*
DcmtkUbuntuvivid*
DcmtkUbuntuwily*
DcmtkUbuntuxenial*
DcmtkUbuntuyakkety*
DcmtkUbuntuzesty*

References