CVE-2024-22373

Executive Summary

CVE-2024-22373: An out‑of‑bounds write in Grassroot DICOM 3.0.23’s JPEG2000Codec::DecodeByStreamsCommon causes a heap buffer overflow when processing a specially crafted DICOM file. An attacker can supply such a file to trigger the vulnerability, potentially leading to arbitrary code execution or denial of service. The flaw is not yet listed in CISA KEV.


Authoritative CVE Metadata - CVSS Base Score: 8.1 (HIGH) - Published: 2024-04-25T15:16:03.590 - Last Modified: 2026-09-10T06:17:01.230

Original Description: An out-of-bounds write vulnerability exists in the JPEG2000Codec::DecodeByStreamsCommon functionality of Mathieu Malaterre Grassroot DICOM 3.0.23. A specially crafted DICOM file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

"Great indeed is the sublimity of the Creative, to which all beings owe their beginning and which permeates all heaven."

— Lao Tzu
Source: NVD