๐Ÿ” CVE Alert

CVE-2025-14607

MEDIUM 6.3

OFFIS DCMTK dcmdata dcbytstr.cc makeDicomByteString memory corruption

CVSS Score
6.3
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability was detected in OFFIS DCMTK up to 3.6.9. Affected by this issue is the function DcmByteString::makeDicomByteString of the file dcmdata/libsrc/dcbytstr.cc of the component dcmdata. The manipulation results in memory corruption. The attack can be launched remotely. Upgrading to version 3.7.0 can resolve this issue. The patch is identified as 4c0e5c10079392c594d6a7abd95dd78ac0aa556a. You should upgrade the affected component.

CWE CWE-119
Vendor offis
Product dcmtk
Published Dec 13, 2025
Last Updated Feb 24, 2026
Stay Ahead of the Next One

Get instant alerts for offis dcmtk

Be the first to know when new medium vulnerabilities affecting offis dcmtk are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

OFFIS / DCMTK
3.6.0 3.6.1 3.6.2 3.6.3 3.6.4 3.6.5 3.6.6 3.6.7 3.6.8 3.6.9

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/?id.336283 vuldb.com: https://vuldb.com/?ctiid.336283 vuldb.com: https://vuldb.com/?submit.705036 support.dcmtk.org: https://support.dcmtk.org/redmine/issues/1184 support.dcmtk.org: https://support.dcmtk.org/redmine/projects/dcmtk/activity?from=2025-12-02 github.com: https://github.com/DCMTK/dcmtk/commit/4c0e5c10079392c594d6a7abd95dd78ac0aa556a support.dcmtk.org: https://support.dcmtk.org/redmine/versions/19

Credits

๐Ÿ” KendrickZou (VulDB User)