Local Access Vulnerability in OFFIS DCMTK Affects DcmQueryRetrieve
CVE-2025-14841

4.8MEDIUM

Key Information:

Vendor

Offis

Status
Vendor
CVE Published:
18 December 2025

What is CVE-2025-14841?

A vulnerability discovered in OFFIS DCMTK versions prior to 3.7.0 involves the DcmQueryRetrieveIndexDatabaseHandle::startFindRequest and startMoveRequest functions. This flaw permits a null pointer dereference when local access is gained. Users are advised to update to version 3.7.0, where this issue has been addressed with the applied patch. Ensuring the system is updated is crucial to prevent potential disruptions or crashes associated with this vulnerability.

Affected Version(s)

DCMTK 3.6.0

DCMTK 3.6.1

DCMTK 3.6.2

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

KendrickZou (VulDB User)
.