PT-2025-3960 · Unknown · Sante Pacs Server

Chizuru Toyama

·

Published

2024-09-03

·

Updated

2025-01-31

·

CVE-2025-0568

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Sante PACS Server (affected versions not specified)
Description The issue is a denial-of-service vulnerability due to memory corruption in the analysis of Sante PACS Server DCM files. This allows remote attackers to create a denial-of-service condition on affected installations without requiring authentication. The problem exists in the parsing of DCM files and results from the lack of proper validation of user-supplied data, leading to a memory corruption condition. An attacker can exploit this to create a denial-of-service condition on the system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Memory Corruption

RCE

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2025-02593
CVE-2025-0568
ZDI-25-049

Affected Products

Sante Pacs Server