When deprecated MC_XML_To_Message() function is used to read a malformed DICOM XML file, it might result in memory access violation.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
The issue is resolved in Merge DICOM Toolkit 5.18.0 release.
Vendor Workaround
As a temporary solution, until a patch is released, it is highly recommended to provide to the MC_XML_To_Message() function only trusted XML files.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-21343 | Use of Out-of-range Pointer Offset vulnerability in Merge DICOM Toolkit C/C++ on Windows. When deprecated MC_XML_To_Message() function is used to read a malformed DICOM XML file, it might result in memory access violation. |
Fri, 06 Dec 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Nozomi
Published:
Updated: 2024-12-06T18:07:33.702Z
Reserved: 2024-01-23T15:02:55.722Z
Link: CVE-2024-23913
Updated: 2024-08-01T23:13:08.699Z
Status : Deferred
Published: 2024-05-03T09:15:07.920
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-23913
No data.
OpenCVE Enrichment
No data.
No weakness.
EUVD