CVE Vulnerabilities

CVE-2021-41689

NULL Pointer Dereference

Published: Jun 28, 2022 | Modified: Nov 03, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

DCMTK through 3.6.6 does not handle string copy properly. Sending specific requests to the dcmqrdb program, it would query its database and copy the result even if the result is null, which can incur a head-based overflow. An attacker can use it to launch a DoS attack.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

NameVendorStart VersionEnd Version
DcmtkOffis*3.6.6 (including)
DcmtkUbuntubionic*
DcmtkUbuntuesm-apps/bionic*
DcmtkUbuntuesm-apps/focal*
DcmtkUbuntuesm-apps/jammy*
DcmtkUbuntuesm-apps/xenial*
DcmtkUbuntufocal*
DcmtkUbuntuimpish*
DcmtkUbuntujammy*
DcmtkUbuntuupstream*

Potential Mitigations

References