CVE-2024-42845

An eval Injection vulnerability in the component invesalius/reader/dicom.py of InVesalius 3.1.99991 through 3.1.99998 allows attackers to execute arbitrary code via loading a crafted DICOM file.
Configurations

No configuration.

History

28 Aug 2024, 16:35

Type Values Removed Values Added
CWE CWE-94
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.0

26 Aug 2024, 12:47

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad de inyección de evaluación en el componente invesalius/reader/dicom.py de InVesalius 3.1.99991 a 3.1.99998 permite a atacantes ejecutar código arbitrario cargando un archivo DICOM manipulado.

23 Aug 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-23 19:15

Updated : 2024-08-28 16:35


NVD link : CVE-2024-42845

Mitre link : CVE-2024-42845

CVE.ORG link : CVE-2024-42845


JSON object : View

Products Affected

No product.

CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')