// For flags

CVE-2015-8397

 

Severity Score

8.2
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

3
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The JPEGLSCodec::DecodeExtent function in MediaStorageAndFileFormat/gdcmJPEGLSCodec.cxx in Grassroots DICOM (aka GDCM) before 2.6.2 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (application crash) via an embedded JPEG-LS image with dimensions larger than the selected region in a (1) two-dimensional or (2) three-dimensional DICOM image file, which triggers an out-of-bounds read.

La función JPEGLSCodec::DecodeExtent en MediaStorageAndFileFormat/gdcmJPEGLSCodec.cxx en Grassroots DICOM (también conocido como GDCM) en versiones anteriores a 2.6.2 permite a atacantes remotos obtener información sensible desde la memoria de proceso o causar una denegación de servicio (caída de aplicación) a través de una imagen JPEG-LS incrustada con dimensiones más grandes que la región seleccionada en un archivo de imagen DICOM (1) de dos dimensiones o (2) de tres dimensiones, lo que desencadena una lectura fuera de rango.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2015-12-02 CVE Reserved
  • 2016-01-11 CVE Published
  • 2024-08-06 CVE Updated
  • 2024-08-06 First Exploit
  • 2024-11-01 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-125: Out-of-bounds Read
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Grassroots Dicom Project
Search vendor "Grassroots Dicom Project"
Grassroots Dicom
Search vendor "Grassroots Dicom Project" for product "Grassroots Dicom"
< 2.6.2
Search vendor "Grassroots Dicom Project" for product "Grassroots Dicom" and version " < 2.6.2"
-
Affected