Description
The JPEGLSCodec::DecodeExtent function in MediaStorageAndFileFormat/gdcmJPEGLSCodec.cxx in Grassroots DICOM (aka GDCM) before 2.6.2 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (application crash) via an embedded JPEG-LS image with dimensions larger than the selected region in a (1) two-dimensional or (2) three-dimensional DICOM image file, which triggers an out-of-bounds read.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2015-8279 | The JPEGLSCodec::DecodeExtent function in MediaStorageAndFileFormat/gdcmJPEGLSCodec.cxx in Grassroots DICOM (aka GDCM) before 2.6.2 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (application crash) via an embedded JPEG-LS image with dimensions larger than the selected region in a (1) two-dimensional or (2) three-dimensional DICOM image file, which triggers an out-of-bounds read. |
References
History
Thu, 21 Aug 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Malaterre
Malaterre grassroots Dicom |
|
| CPEs | cpe:2.3:a:malaterre:grassroots_dicom:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Grassroots Dicom Project
Grassroots Dicom Project grassroots Dicom |
Malaterre
Malaterre grassroots Dicom |
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T08:13:32.679Z
Reserved: 2015-12-02T00:00:00.000Z
Link: CVE-2015-8397
No data.
Status : Modified
Published: 2016-01-12T20:59:03.700
Modified: 2026-05-06T22:30:45.220
Link: CVE-2015-8397
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD