CVE-2024-27629: Rordenlab DCM2NIIX
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
An issue in dc2niix before v.1.0.20240202 allows a local attacker to execute arbitrary code via the generated file name is not properly escaped and injected into a system call when certain types of compression are used.
Affected products
- Rordenlab DCM2NIIX: before 1.0.20240202 (fixed in 1.0.20240202)
Published 2024-06-28. Last modified 2026-06-17.