An out-of-bounds write vulnerability exists in the JPEG2000Codec::DecodeByStreamsCommon functionality of Mathieu Malaterre Grassroot DICOM 3.0.23. A specially crafted DICOM file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

Project Subscriptions

Vendors Products
Fedoraproject Subscribe
Grassroots Dicom Project Subscribe
Grassroots Dicom Subscribe
Malaterre Subscribe
Grassroots Dicom Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2024-19930 An out-of-bounds write vulnerability exists in the JPEG2000Codec::DecodeByStreamsCommon functionality of Mathieu Malaterre Grassroot DICOM 3.0.23. A specially crafted DICOM file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 16 Dec 2025 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Malaterre
Malaterre grassroots Dicom
CPEs cpe:2.3:a:grassroots_dicom_project:grassroots_dicom:3.0.23:*:*:*:*:*:*:* cpe:2.3:a:malaterre:grassroots_dicom:3.0.23:*:*:*:*:*:*:*
Vendors & Products Malaterre
Malaterre grassroots Dicom

Tue, 04 Nov 2025 18:30:00 +0000


Tue, 04 Nov 2025 18:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:grassroots_dicom_project:grassroots_dicom:*:*:*:*:*:*:*:*
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 21 Aug 2025 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Fedoraproject
Fedoraproject fedora
Grassroots Dicom Project
Grassroots Dicom Project grassroots Dicom
Weaknesses CWE-787
CPEs cpe:2.3:a:grassroots_dicom_project:grassroots_dicom:3.0.23:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:*
Vendors & Products Fedoraproject
Fedoraproject fedora
Grassroots Dicom Project
Grassroots Dicom Project grassroots Dicom

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: talos

Published:

Updated: 2025-11-04T17:14:17.202Z

Reserved: 2024-01-31T18:27:18.005Z

Link: CVE-2024-22373

cve-icon Vulnrichment

Updated: 2025-11-04T17:14:17.202Z

cve-icon NVD

Status : Analyzed

Published: 2024-04-25T15:16:03.590

Modified: 2025-12-16T19:17:37.730

Link: CVE-2024-22373

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses