PT-2025-51987 · Offis+1 · Dcmtk+1

·

CVE-2025-14841

·

Published

2025-12-18

·

Updated

2026-02-16

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions OFFIS DCMTK versions up to 3.6.9
Description A flaw exists in the DCMTK library, specifically within the DcmQueryRetrieveIndexDatabaseHandle::startFindRequest and DcmQueryRetrieveIndexDatabaseHandle::startMoveRequest functions located in the dcmqrdb/libsrc/dcmqrdbi.cc file of the dcmqrscp component. This manipulation can lead to a null pointer dereference. Local access is required for exploitation.
Recommendations Upgrade to version 3.7.0 to resolve this issue.

Exploit

Fix

Improper Resource Release

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-07521
CVE-2025-14841
MGASA-2026-0040
OPENSUSE-SU-2026:10006-1

Affected Products

Dcmtk
Debian