PT-2026-97802 · Dcmtk · Dcmtk
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
DCMTK versions prior to 3.7.1
Description
A heap over-read occurs in the ConcatenationLoader when copying pixel data frames. The issue arises because the software fails to validate the
PixelData buffer length against the declared NumberOfFrames. An attacker can use a specially crafted DICOM instance that declares more frames than the buffer actually contains, leading to an application crash or the leakage of adjacent heap memory.Recommendations
Update to a version newer than 3.7.0.
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dcmtk