PT-2025-2931 · Offis+4 · Dcmtk+4

Emmanuel Tacheau

·

Published

2024-12-16

·

Updated

2025-09-29

·

CVE-2024-52333

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OFFIS DCMTK version 3.6.8
Description An improper array index validation issue exists in the determineMinMax functionality. A specially crafted DICOM file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this issue, potentially exploiting the improper array index validation in the determineMinMax function.
Recommendations For OFFIS DCMTK version 3.6.8, consider disabling the determineMinMax function until a patch is available to prevent potential out-of-bounds writes. Restrict access to handling DICOM files to minimize the risk of exploitation. Avoid using potentially malicious DICOM files until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

ALT-PU-2025-6888
ALT-PU-2025-8713
ALT-PU-2025-8855
BDU:2025-07883
CVE-2024-52333
DLA-4038-1
DLA-4038-2
MGASA-2025-0017
OPENSUSE-SU-2025:0053-1
OPENSUSE-SU-2025:14643-1

Affected Products

Alt Linux
Astra Linux
Dcmtk
Debian
Red Os