PT-2025-51987 · Offis+1 · Dcmtk+1

Kendrickzou

·

Published

2025-12-18

·

Updated

2026-02-16

·

CVE-2025-14841

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions OFFIS DCMTK versions up to 3.6.9
Description A flaw exists in the DCMTK library, specifically within the DcmQueryRetrieveIndexDatabaseHandle::startFindRequest and DcmQueryRetrieveIndexDatabaseHandle::startMoveRequest functions located in the dcmqrdb/libsrc/dcmqrdbi.cc file of the dcmqrscp component. This manipulation can lead to a null pointer dereference. Local access is required for exploitation.
Recommendations Upgrade to version 3.7.0 to resolve this issue.

Fix

NULL Pointer Dereference

Improper Resource Release

Weakness Enumeration

Related Identifiers

BDU:2026-07521
CVE-2025-14841
MGASA-2026-0040
OPENSUSE-SU-2026:10006-1

Affected Products

Dcmtk
Debian