CVE Vulnerabilities

CVE-2013-6825

Published: Jun 10, 2014 | Modified: Nov 07, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

(1) movescu.cc and (2) storescp.cc in dcmnet/apps/, (3) dcmnet/libsrc/scp.cc, (4) dcmwlm/libsrc/wlmactmg.cc, (5) dcmprscp.cc and (6) dcmpsrcv.cc in dcmpstat/apps/, (7) dcmpstat/tests/msgserv.cc, and (8) dcmqrdb/apps/dcmqrscp.cc in DCMTK 3.6.1 and earlier does not check the return value of the setuid system call, which allows local users to gain privileges by creating a large number of processes.

Affected Software

Name Vendor Start Version End Version
Dcmtk Offis * 3.6.1 (including)
Dcmtk Offis 3.5.1 (including) 3.5.1 (including)
Dcmtk Offis 3.5.2 (including) 3.5.2 (including)
Dcmtk Offis 3.5.2a (including) 3.5.2a (including)
Dcmtk Offis 3.5.3 (including) 3.5.3 (including)
Dcmtk Offis 3.5.4 (including) 3.5.4 (including)
Dcmtk Offis 3.6.0 (including) 3.6.0 (including)

References