CVE-2024-24794

A use-after-free vulnerability exists in the DICOM Element Parsing as implemented in Imaging Data Commons libdicom 1.0.5. A specially crafted DICOM file can cause premature freeing of memory that is used later. To trigger this vulnerability, an attacker would need to induce the vulnerable application to process a malicious DICOM image.The Use-After-Free happens in the `parse_meta_sequence_end()` parsing the Sequence Value Represenations.
Configurations

Configuration 1 (hide)

cpe:2.3:a:nih:libdicom:1.0.5:*:*:*:*:*:*:*

History

12 Feb 2025, 18:51

Type Values Removed Values Added
First Time Nih
Nih libdicom
CPE cpe:2.3:a:nih:libdicom:1.0.5:*:*:*:*:*:*:*
References () https://talosintelligence.com/vulnerability_reports/TALOS-2024-1931 - () https://talosintelligence.com/vulnerability_reports/TALOS-2024-1931 - Exploit, Third Party Advisory

21 Nov 2024, 08:59

Type Values Removed Values Added
References () https://talosintelligence.com/vulnerability_reports/TALOS-2024-1931 - () https://talosintelligence.com/vulnerability_reports/TALOS-2024-1931 -

20 Feb 2024, 18:15

Type Values Removed Values Added
References
  • {'url': 'https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-1931', 'source': 'talos-cna@cisco.com'}
Summary
  • (es) Existe una vulnerabilidad de uuse-after-free en DICOM Element Parsing implementado en Imaging Data Commons libdicom 1.0.5. Un archivo DICOM especialmente manipulado puede provocar la liberación prematura de memoria que se utilizará más adelante. Para desencadenar esta vulnerabilidad, un atacante necesitaría inducir a la aplicación vulnerable a procesar una imagen DICOM maliciosa. El Use-After-Free ocurre en `parse_meta_sequence_end()` analizando las representaciones de valores de secuencia.

20 Feb 2024, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-20 11:15

Updated : 2025-02-12 18:51


NVD link : CVE-2024-24794

Mitre link : CVE-2024-24794

CVE.ORG link : CVE-2024-24794


JSON object : View

Products Affected

nih

  • libdicom
CWE
CWE-416

Use After Free