PT-2025-11451 · Dcmtk+4 · Dcmtk+4
0X20Z
·
Published
2025-03-16
·
Updated
2025-09-10
·
CVE-2025-2357
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
DCMTK version 3.6.9
Description:
A critical vulnerability was found in the dcmjpls JPEG-LS Decoder component of DCMTK, affecting unknown code and leading to memory corruption. The attack can be initiated remotely. The manipulation with the
dcmjpls component can cause memory corruption.Recommendations:
To fix this issue, it is recommended to apply a patch, specifically the patch named
3239a7915, to DCMTK version 3.6.9. As a temporary workaround, consider disabling the dcmjpls JPEG-LS Decoder component until a patch is available. Restrict access to the vulnerable component to minimize the risk of exploitation.Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Dcmtk
Debian
Red Os