Description
A flaw has been found in OFFIS DCMTK up to 3.6.9. The impacted element is the function DcmQueryRetrieveIndexDatabaseHandle::startFindRequest/DcmQueryRetrieveIndexDatabaseHandle::startMoveRequest in the library dcmqrdb/libsrc/dcmqrdbi.cc of the component dcmqrscp. This manipulation causes null pointer dereference. The attack requires local access. Upgrading to version 3.7.0 is sufficient to resolve this issue. Patch name: ffb1a4a37d2c876e3feeb31df4930f2aed7fa030. You should upgrade the affected component.
Problem types
Product status
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.6.9
3.7.0
Timeline
| 2025-12-17: | Advisory disclosed |
| 2025-12-17: | VulDB entry created |
| 2025-12-17: | VulDB entry last update |
Credits
KendrickZou (VulDB User)
References
vuldb.com/?id.337004 (VDB-337004 | OFFIS DCMTK dcmqrscp dcmqrdbi.cc startMoveRequest null pointer dereference)
vuldb.com/?ctiid.337004 (VDB-337004 | CTI Indicators (IOB, IOC, IOA))
vuldb.com/?submit.714605 (Submit #714605 | OFFIS DCMTK 3.6.9 Denial of Service)
vuldb.com/?submit.714634 (Submit #714634 | OFFIS DCMTK 3.6.9 Denial of Service (Duplicate))
support.dcmtk.org/redmine/issues/1183
github.com/...ommit/ffb1a4a37d2c876e3feeb31df4930f2aed7fa030
github.com/DCMTK/dcmtk/releases/tag/DCMTK-3.7.0
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.