Description
Rubo DICOM Viewer 2.0 contains a buffer overflow vulnerability in the DICOM server name input field that allows attackers to overwrite Structured Exception Handler (SEH). Attackers can craft a malicious text file with carefully constructed payload to execute arbitrary code by overwriting SEH and triggering remote code execution.
Problem types
Product status
Credits
bzyo
References
www.exploit-db.com/exploits/48351 (ExploitDB-48351)
web.archive.org/...p://www.rubomedical.com/dicom_viewer.html (Archived Rubo DICOM Viewer Product Page)
www.vulncheck.com/...s/rubo-dicom-viewer-buffer-overflow-seh (VulnCheck Advisory: Rubo DICOM Viewer 2.0 - Buffer Overflow (SEH))