Vulnerability Description
OFFIS DCMTK's (All versions prior to 3.6.7) has a NULL pointer dereference vulnerability while processing DICOM files, which may result in a denial-of-service condition.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Offis | Dcmtk | < 3.6.7 |
Related Weaknesses (CWE)
References
- https://lists.debian.org/debian-lts-announce/2024/06/msg00022.html
- https://www.cisa.gov/uscert/ics/advisories/icsma-22-174-01MitigationThird Party AdvisoryUS Government Resource
- https://lists.debian.org/debian-lts-announce/2024/06/msg00022.html
- https://lists.debian.org/debian-lts-announce/2025/01/msg00032.html
- https://www.cisa.gov/uscert/ics/advisories/icsma-22-174-01MitigationThird Party AdvisoryUS Government Resource
FAQ
What is CVE-2022-2121?
CVE-2022-2121 is a vulnerability with a CVSS score of 7.5 (HIGH). OFFIS DCMTK's (All versions prior to 3.6.7) has a NULL pointer dereference vulnerability while processing DICOM files, which may result in a denial-of-service condition.
How severe is CVE-2022-2121?
CVE-2022-2121 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-2121?
Check the references section above for vendor advisories and patch information. Affected products include: Offis Dcmtk.