פגיעות בשרת Orthanc DICOM: כתיבה מחוץ לטווח הקצאת זיכרון
Orthanc DICOM Server
>פגיעות קריטית בשרת Orthanc DICOM מאפשרת למתקפה מאומת לכתוב מעבר לסוף הקצאת זיכרון (heap allocation). הדבר מוביל לקריסת התהליך ולמצב מניעת…
◆ סיכום AI
פגיעות קריטית בשרת Orthanc DICOM מאפשרת למתקפה מאומת לכתוב מעבר לסוף הקצאת זיכרון (heap allocation). הדבר מוביל לקריסת התהליך ולמצב מניעת שירות (DoS) באמצעות תמונה (PNG/JPEG) מרושעת. יש לבדוק עדכונים עבור גרסאות פגיעות כדי למנוע ניצול.
# מהמקור
View CSAF Summary Successful exploitation of this vulnerability could allow an authenticated remote attacker to write past the end of a heap allocation when Orthanc decodes an attacker-supplied PNG or JPEG image, resulting in a crash of the Orthanc process and a denial-of-service condition. The following versions of Orthanc DICOM Server are affected: Orthanc DICOM Server CVSS <th role="columnh