Denial of Service Vulnerability in DCMTK by Offis
CVE-2025-25475
7.5HIGH
What is CVE-2025-25475?
A vulnerability in DCMTK, specifically in the /libsrc/dcrleccd.cc component, enables attackers to induce a Denial of Service (DoS) by exploiting a NULL pointer dereference. This vulnerability arises when specially crafted DICOM files are processed, potentially disrupting service availability for users relying on this medical image processing toolkit.