A vulnerability was detected in OFFIS DCMTK up to 3.6.9. Affected by this issue is the function DcmByteString::makeDicomByteString of the file dcmdata/libsrc/dcbytstr.cc of the component dcmdata. The manipulation results in memory corruption. The attack can be launched remotely. Upgrading to version 3.7.0 can resolve this issue. The patch is identified as 4c0e5c10079392c594d6a7abd95dd78ac0aa556a. You should upgrade the affected component.
Metrics
Affected Vendors & Products
References
History
Sun, 14 Dec 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Offis
Offis dcmtk |
|
| Vendors & Products |
Offis
Offis dcmtk |
Sat, 13 Dec 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was detected in OFFIS DCMTK up to 3.6.9. Affected by this issue is the function DcmByteString::makeDicomByteString of the file dcmdata/libsrc/dcbytstr.cc of the component dcmdata. The manipulation results in memory corruption. The attack can be launched remotely. Upgrading to version 3.7.0 can resolve this issue. The patch is identified as 4c0e5c10079392c594d6a7abd95dd78ac0aa556a. You should upgrade the affected component. | |
| Title | OFFIS DCMTK dcmdata dcbytstr.cc makeDicomByteString memory corruption | |
| Weaknesses | CWE-119 | |
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2025-12-13T13:02:07.302Z
Updated: 2025-12-13T13:02:07.302Z
Reserved: 2025-12-12T19:54:18.039Z
Link: CVE-2025-14607
No data.
Status : Awaiting Analysis
Published: 2025-12-13T16:16:52.840
Modified: 2025-12-15T18:22:13.783
Link: CVE-2025-14607
No data.
ReportizFlow