An incorrect type conversion vulnerability exists in the DVPSSoftcopyVOI_PList::createFromImage functionality of OFFIS DCMTK 3.6.8. A specially crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
The product does not correctly convert an object, resource, or structure from one type to a different type.
| Name | Vendor | Start Version | End Version | 
|---|---|---|---|
| Dcmtk | Offis | 3.6.8 (including) | 3.6.8 (including) | 
| Dcmtk | Ubuntu | esm-apps/focal | * | 
| Dcmtk | Ubuntu | esm-apps/jammy | * | 
| Dcmtk | Ubuntu | focal | * | 
| Dcmtk | Ubuntu | jammy | * | 
| Dcmtk | Ubuntu | oracular | * |