PT-2025-2776 · Offis+4 · Offis Dcmtk+4

Emmanuel Tacheau

·

Published

2024-12-16

·

Updated

2025-09-29

·

CVE-2024-47796

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: OFFIS DCMTK version 3.6.8
Description: An improper array index validation vulnerability exists in the nowindow functionality of OFFIS DCMTK. A specially crafted DICOM file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability.
Recommendations: For OFFIS DCMTK version 3.6.8, consider upgrading to a newer version that contains a fix for this vulnerability, such as dcmtk-3.6.9-1.1. As a temporary workaround, consider restricting access to the nowindow functionality to minimize the risk of exploitation.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2025-6888
ALT-PU-2025-8713
ALT-PU-2025-8855
BDU:2025-07883
BDU:2025-08003
CVE-2024-47796
DLA-4038-1
DLA-4038-2
DLA-4227-1
MGASA-2025-0017
OPENSUSE-SU-2025:0053-1
OPENSUSE-SU-2025:14643-1

Affected Products

Alt Linux
Astra Linux
Debian
Offis Dcmtk
Red Os