A security flaw has been discovered in OFFIS DCMTK up to 3.7.0. This impacts the function executeOnReception/executeOnEndOfStudy of the file dcmnet/apps/storescp.cc of the component storescp. Performing a manipulation results in os command injection. Remote exploitation of the attack is possible. The patch is named edbb085e45788dccaf0e64d71534cfca925784b8. Applying a patch is the recommended action to fix this issue.
Metrics
Affected Vendors & Products
References
History
Mon, 06 Apr 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security flaw has been discovered in OFFIS DCMTK up to 3.7.0. This impacts the function executeOnReception/executeOnEndOfStudy of the file dcmnet/apps/storescp.cc of the component storescp. Performing a manipulation results in os command injection. Remote exploitation of the attack is possible. The patch is named edbb085e45788dccaf0e64d71534cfca925784b8. Applying a patch is the recommended action to fix this issue. | |
| Title | OFFIS DCMTK storescp storescp.cc executeOnEndOfStudy os command injection | |
| First Time appeared |
Offis
Offis dcmtk |
|
| Weaknesses | CWE-77 CWE-78 |
|
| CPEs | cpe:2.3:a:offis:dcmtk:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Offis
Offis dcmtk |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-04-06T14:15:11.214Z
Reserved: 2026-04-06T07:55:05.388Z
Link: CVE-2026-5663
No data.
Status : Received
Published: 2026-04-06T15:17:16.253
Modified: 2026-04-06T15:17:16.253
Link: CVE-2026-5663
No data.
OpenCVE Enrichment
No data.