Home
HIGH: 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H 3.024
affected
Description
An out-of-bounds read vulnerability exists in the RLECodec::DecodeByStreams functionality of Grassroot DICOM 3.024. A specially crafted DICOM file can lead to leaking heap data. An attacker can provide a malicious file to trigger this vulnerability.
Problem types
CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
Product status
Credits
Discovered by Emmanuel Tacheau of Cisco Talos.
References
www.talosintelligence.com/...ability_reports/TALOS-2025-2214
talosintelligence.com/vulnerability_reports/TALOS-2025-2214
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.