CVE-2025-14607
OFFIS DCMTK dcmdata dcbytstr.cc makeDicomByteString memory corruption
CVSS Score
6.3
EPSS Score
0.0%
EPSS Percentile
0th
A vulnerability was detected in OFFIS DCMTK up to 3.6.9. Affected by this issue is the function DcmByteString::makeDicomByteString of the file dcmdata/libsrc/dcbytstr.cc of the component dcmdata. The manipulation results in memory corruption. The attack can be launched remotely. Upgrading to version 3.7.0 can resolve this issue. The patch is identified as 4c0e5c10079392c594d6a7abd95dd78ac0aa556a. You should upgrade the affected component.
| CWE | CWE-119 |
| Vendor | offis |
| Product | dcmtk |
| Published | Dec 13, 2025 |
| Last Updated | Feb 24, 2026 |
Stay Ahead of the Next One
Get instant alerts for offis dcmtk
Be the first to know when new medium vulnerabilities affecting offis dcmtk are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
OFFIS / DCMTK
3.6.0 3.6.1 3.6.2 3.6.3 3.6.4 3.6.5 3.6.6 3.6.7 3.6.8 3.6.9
References
vuldb.com: https://vuldb.com/?id.336283 vuldb.com: https://vuldb.com/?ctiid.336283 vuldb.com: https://vuldb.com/?submit.705036 support.dcmtk.org: https://support.dcmtk.org/redmine/issues/1184 support.dcmtk.org: https://support.dcmtk.org/redmine/projects/dcmtk/activity?from=2025-12-02 github.com: https://github.com/DCMTK/dcmtk/commit/4c0e5c10079392c594d6a7abd95dd78ac0aa556a support.dcmtk.org: https://support.dcmtk.org/redmine/versions/19
Credits
๐ KendrickZou (VulDB User)