CVE-2024-24793

A use-after-free vulnerability exists in the DICOM Element Parsing as implemented in Imaging Data Commons libdicom 1.0.5. A specially crafted DICOM file can cause premature freeing of memory that is used later. To trigger this vulnerability, an attacker would need to induce the vulnerable application to process a malicious DICOM image.The Use-After-Free happens in the `parse_meta_element_create()` parsing the elements in the File Meta Information header.
Configurations

Configuration 1 (hide)

cpe:2.3:a:nih:libdicom:1.0.5:*:*:*:*:*:*:*

History

12 Feb 2025, 18:52

Type Values Removed Values Added
CPE cpe:2.3:a:nih:libdicom:1.0.5:*:*:*:*:*:*:*
References () https://talosintelligence.com/vulnerability_reports/TALOS-2024-1931 - () https://talosintelligence.com/vulnerability_reports/TALOS-2024-1931 - Exploit, Third Party Advisory
First Time Nih
Nih libdicom

21 Nov 2024, 08:59

Type Values Removed Values Added
References () https://talosintelligence.com/vulnerability_reports/TALOS-2024-1931 - () https://talosintelligence.com/vulnerability_reports/TALOS-2024-1931 -

20 Feb 2024, 18:15

Type Values Removed Values Added
References
  • {'url': 'https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-1931', 'source': 'talos-cna@cisco.com'}
Summary
  • (es) Existe una vulnerabilidad de use-after-free en DICOM Element Parsing implementado en Imaging Data Commons libdicom 1.0.5. Un archivo DICOM especialmente manipulado puede provocar la liberación prematura de memoria que se utilizará más adelante. Para desencadenar esta vulnerabilidad, un atacante necesitaría inducir a la aplicación vulnerable a procesar una imagen DICOM maliciosa. El Use-After-Free ocurre en `parse_meta_element_create()` analizando los elementos en el encabezado de metainformación del archivo.

20 Feb 2024, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-20 11:15

Updated : 2025-02-12 18:52


NVD link : CVE-2024-24793

Mitre link : CVE-2024-24793

CVE.ORG link : CVE-2024-24793


JSON object : View

Products Affected

nih

  • libdicom
CWE
CWE-416

Use After Free