Stack-based Buffer Overflow in Sante PACS Server by OpenSSL
CVE-2025-2263
9.8CRITICAL
What is CVE-2025-2263?
A stack-based buffer overflow vulnerability has been identified in Sante PACS Server during the login process. When an unauthenticated remote attacker provides a long encrypted username or password, the OpenSSL function EVP_DecryptUpdate may write beyond the bounds of the fixed 0x80-byte stack buffer. This could lead to arbitrary code execution and compromise the security of the server.
Affected Version(s)
Sante PACS Server 4.1.0
Sante PACS Server 4.2.0