PT-2025-11451 · Dcmtk+4 · Dcmtk+4

0X20Z

·

Published

2025-03-16

·

Updated

2025-09-10

·

CVE-2025-2357

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: DCMTK version 3.6.9
Description: A critical vulnerability was found in the dcmjpls JPEG-LS Decoder component of DCMTK, affecting unknown code and leading to memory corruption. The attack can be initiated remotely. The manipulation with the dcmjpls component can cause memory corruption.
Recommendations: To fix this issue, it is recommended to apply a patch, specifically the patch named 3239a7915, to DCMTK version 3.6.9. As a temporary workaround, consider disabling the dcmjpls JPEG-LS Decoder component until a patch is available. Restrict access to the vulnerable component to minimize the risk of exploitation.

Exploit

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

ALT-PU-2025-8713
ALT-PU-2025-8855
BDU:2025-11441
CVE-2025-2357
DLA-4227-1
MGASA-2025-0117
OPENSUSE-SU-2025:14901-1

Affected Products

Alt Linux
Astra Linux
Dcmtk
Debian
Red Os