{"id":"CVE-2024-22373","title":"An out-of-bounds write vulnerability exists in the JPEG2000Codec::DecodeByStreamsCommon functionality of Mathieu Malaterre Grassroot DICOM 3.0.23","summary":"An out-of-bounds write vulnerability exists in the JPEG2000Codec::DecodeByStreamsCommon functionality of Mathieu Malaterre Grassroot DICOM 3.0.23. A specially crafted DICOM file can lead to a heap buffer overflow. An attacker can provide…","severity":"high","cvss":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-119","CWE-787"],"vendor":"malaterre","product":"grassroots_dicom","affected":["grassroots_dicom = 3.0.23","fedora = 38","fedora = 39","fedora = 40"],"published":"2024-04-25","updated":"2026-09-10","sourceUpdated":"2026-09-10T06:17:01.230","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2024-22373","references":[{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BZJ4IG7EXMSMPHTK5ZFASCW6MHSOVZOE/","label":"talos-cna@cisco.com"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/N5HXUKUJ7SG3TK456SGUWVZ4Z5D7JKOL/","label":"talos-cna@cisco.com"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WJA7QWWZWMY4AQFR35EA7S3CFVUTOQYG/","label":"talos-cna@cisco.com"},{"url":"https://talosintelligence.com/vulnerability_reports/TALOS-2024-1935","label":"talos-cna@cisco.com"},{"url":"http://www.openwall.com/lists/oss-security/2026/09/10/13","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BZJ4IG7EXMSMPHTK5ZFASCW6MHSOVZOE/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/N5HXUKUJ7SG3TK456SGUWVZ4Z5D7JKOL/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WJA7QWWZWMY4AQFR35EA7S3CFVUTOQYG/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://talosintelligence.com/vulnerability_reports/TALOS-2024-1935","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-1935","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-08-24T13:36:06.687320Z"},"epss":0.01583,"epssPercentile":0.74062,"ingestedAt":"2026-08-24T15:05:56.178Z","slug":"CVE-2024-22373","body":"## Overview\n\nAn out-of-bounds write vulnerability exists in the JPEG2000Codec::DecodeByStreamsCommon functionality of Mathieu Malaterre Grassroot DICOM 3.0.23. A specially crafted DICOM file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.\n\n## Affected\n\n- `grassroots_dicom = 3.0.23`\n- `fedora = 38`\n- `fedora = 39`\n- `fedora = 40`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":45,"depthScoreParts":{"impact":44.6,"likelihood":0.3,"exploitation":0,"ransomware":0},"changes":[]}