OFFIS DCMTK Toolkit
This CISA advisory details vulnerabilities within the OFFIS DCMTK Toolkit (<=3.7.0) that could allow an attacker to perform actions like file writing, unauthorized data access, memory exhaustion, and system crashes. The vulnerabilities, primarily related to path traversal and memory leaks, are exploitable by unauthenticated remote attackers. Users are advised to immediately update to the latest version to mitigate the risk.
The vulnerabilities identified in the OFFIS DCMTK Toolkit relate to how the software handles file paths and manages memory. Specifically, an attacker could leverage a path traversal flaw to write files outside of the intended directory, potentially gaining unauthorized access to sensitive data. Furthermore, the toolkit is susceptible to memory leaks, where an attacker can repeatedly send crafted requests to exhaust system resources and ultimately crash the affected processes. These issues are exacerbated in single-process deployments, leading to rapid memory consumption and service termination. The vulnerabilities are actively being addressed by the maintainer, who has released a fix.