CVE-2021-41689

HIGH

DCMTK <= 3.6.6 - Denial of Service via Null String Copy in dcmqrdb

Title source: llm
STIX 2.1

Description

DCMTK through 3.6.6 does not handle string copy properly. Sending specific requests to the dcmqrdb program, it would query its database and copy the result even if the result is null, which can incur a head-based overflow. An attacker can use it to launch a DoS attack.

Scores

CVSS v3 7.5
EPSS 0.0169
EPSS Percentile 74.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-476
Status published
Products (1)
offis/dcmtk < 3.6.6
Published Jun 28, 2022
Tracked Since Feb 18, 2026