PT-2025-42893 · Dcmtk+1 · Dcmtk+1

Zh_Vul

·

Published

2025-10-21

·

Updated

2025-11-03

·

CVE-2022-4981

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions DCMTK versions up to 3.6.7
Description A flaw exists in DCMTK where manipulation of the DcmQueryRetrieveConfig::readPeerList function within the /dcmqrcnf.cc file of the dcmqrscp component can lead to a null pointer dereference. This issue requires local access to exploit. The exploit is publicly available.
Recommendations Upgrade to version 3.6.8 to resolve this issue.

Exploit

Fix

Improper Resource Release

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-16066
CVE-2022-4981
DLA-4363-1

Affected Products

Dcmtk
Debian