Description
A security flaw has been discovered in OFFIS DCMTK up to 3.7.0. This impacts the function executeOnReception/executeOnEndOfStudy of the file dcmnet/apps/storescp.cc of the component storescp. Performing a manipulation results in os command injection. Remote exploitation of the attack is possible. The patch is named edbb085e45788dccaf0e64d71534cfca925784b8. Applying a patch is the recommended action to fix this issue.
Problem types
Product status
3.1
3.2
3.3
3.4
3.5
3.6
3.7.0
Timeline
| 2026-04-06: | Advisory disclosed |
| 2026-04-06: | VulDB entry created |
| 2026-04-06: | VulDB entry last update |
Credits
Simon Weber (Machine Spirits)
Volker Schönefeld (Machine Spirits)
simon4machinespirits (VulDB User)
References
vuldb.com/vuln/355486 (VDB-355486 | OFFIS DCMTK storescp storescp.cc executeOnEndOfStudy os command injection)
vuldb.com/vuln/355486/cti (VDB-355486 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/submit/786061 (Submit #786061 | OFFIS DCMTK up to 3.7.0 OS Command Injection)
machinespirits.com/advisory/2e1627/
support.dcmtk.org/redmine/issues/1194
github.com/...ommit/edbb085e45788dccaf0e64d71534cfca925784b8